« Volver al listado

CVE-2024-37313

Estado: AnalizadaAlta (7.5)—

Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and Nextcloud Enterprise Server is upgraded to 21.0.9.17, 22.2.10.22, 23.0.12.17, 24.0.12.13, 25.0.13.8, 26.0.13, 27.1.8 or 28.0.4.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-37313",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-37313",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-06-14T15:49:53.416668Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "nextcloud",
          "product": "security-advisories",
          "versions": [
            {
              "status": "affected",
              "version": ">= 26.0.0, < 26.0.13"
            },
            {
              "status": "affected",
              "version": ">= 27.0.0, < 27.1.8"
            },
            {
              "status": "affected",
              "version": ">= 28.0.0, < 28.0.4"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:nextcloud:server:*:*:*:*:*:*:*:*"
          ],
          "vendor": "nextcloud",
          "product": "server",
          "versions": [
            {
              "status": "affected",
              "version": "26.0.0",
              "lessThan": "26.0.13",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "27.0.0",
              "lessThan": "27.1.8",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "28.0.0",
              "lessThan": "28.0.4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-06-14T15:15:51.427",
  "references": [
    {
      "url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nextcloud/server/pull/44276",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://hackerone.com/reports/2419776",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/nextcloud/server/pull/44276",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://hackerone.com/reports/2419776",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and Nextcloud Enterprise Server is upgraded to 21.0.9.17, 22.2.10.22, 23.0.12.17, 24.0.12.13, 25.0.13.8, 26.0.13, 27.1.8 or 28.0.4."
    },
    {
      "lang": "es",
      "value": "El servidor Nextcloud es un sistema de nube personal autohospedado. En algunas circunstancias, fue posible omitir el segundo factor de 2FA después de proporcionar correctamente las credenciales del usuario. Se recomienda actualizar Nextcloud Server a 26.0.13, 27.1.8 o 28.0.4 y Nextcloud Enterprise Server a 21.0.9.17, 22.2.10.22, 23.0.12.17, 24.0.12.13, 25.0.13.8, 26.0. 13, 27.1.8 o 28.0.4."
    }
  ],
  "lastModified": "2026-06-17T07:38:07.420",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82FA477E-77B0-4EFA-B26B-05C4EBF34B72",
              "versionEndExcluding": "21.0.9.17",
              "versionStartIncluding": "21.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "714AFD9B-988F-4AA3-AD34-7F003E2204EF",
              "versionEndExcluding": "22.2.10.22",
              "versionStartIncluding": "22.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED4378AE-1AD4-4E15-A64C-E4028FCD098F",
              "versionEndExcluding": "23.0.12.17",
              "versionStartIncluding": "23.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20A172FB-2E26-4ADD-BA55-0ECC5E5FCFD1",
              "versionEndExcluding": "24.0.12.13",
              "versionStartIncluding": "24.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D2923A6-9A3C-4B66-82D4-E02A0E8F16A4",
              "versionEndExcluding": "25.0.13.8",
              "versionStartIncluding": "25.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F643317-2586-435E-8D89-721BC6161691",
              "versionEndExcluding": "26.0.13",
              "versionStartIncluding": "26.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6909C63C-3755-4B68-B90E-4C5E14C78787",
              "versionEndExcluding": "26.0.13",
              "versionStartIncluding": "26.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8696DA00-5B0C-45F5-BD50-9FF1F5E4646F",
              "versionEndExcluding": "27.1.8",
              "versionStartIncluding": "27.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6C25B03-B587-4F48-BE81-052AF67E2045",
              "versionEndExcluding": "27.1.8",
              "versionStartIncluding": "27.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3A816F7-5D5E-43CB-9C53-E4C5B1344C84",
              "versionEndExcluding": "28.0.4",
              "versionStartIncluding": "28.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E04001FE-890B-4D94-B679-B0854E840F39",
              "versionEndExcluding": "28.0.4",
              "versionStartIncluding": "28.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}