CVE-2024-22401
Estado: ModificadaMedia (4.3)—
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.46%
- Percentil entre todas las CVEs puntuadas: 38
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-281
Referencias
- https://github.com/nextcloud/guests/pull/1082
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wr87-hx3w-29hh
- https://hackerone.com/reports/2250398
- https://github.com/nextcloud/guests/pull/1082
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wr87-hx3w-29hh
- https://hackerone.com/reports/2250398
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-22401",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-22401",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-01-22T15:12:49.328732Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 4.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.3
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "nextcloud",
"product": "security-advisories",
"versions": [
{
"status": "affected",
"version": ">= 2.4.0, < 2.4.1"
},
{
"status": "affected",
"version": ">= 2.5.0, < 2.5.1"
},
{
"status": "affected",
"version": ">= 3.0.0, < 3.0.1"
}
]
}
]
}
],
"published": "2024-01-18T21:15:08.343",
"references": [
{
"url": "https://github.com/nextcloud/guests/pull/1082",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wr87-hx3w-29hh",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://hackerone.com/reports/2250398",
"tags": [
"Permissions Required",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nextcloud/guests/pull/1082",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wr87-hx3w-29hh",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://hackerone.com/reports/2250398",
"tags": [
"Permissions Required",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-281"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability."
},
{
"lang": "es",
"value": "La aplicación para invitados Nextcloud es una utilidad para crear usuarios invitados que solo pueden ver los archivos compartidos con ellos. En las versiones afectadas, los usuarios podían cambiar la lista permitida de aplicaciones, permitiéndoles usar aplicaciones que no estaban destinadas a ser utilizadas. Se recomienda actualizar la aplicación Invitados a 2.4.1, 2.5.1 o 3.0.1. No se conocen workarounds para esta vulnerabilidad."
}
],
"lastModified": "2026-06-17T07:11:20.300",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nextcloud:guests:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "96F65F1E-19D7-4B72-8618-A7D8BE0578E4",
"versionEndExcluding": "2.4.1"
},
{
"criteria": "cpe:2.3:a:nextcloud:guests:2.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57F1277A-3A44-4CDF-AF3C-B8A5AE395549"
},
{
"criteria": "cpe:2.3:a:nextcloud:guests:3.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F64336EF-9FEA-4DC2-B44A-70470D52632B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}