CVE-2022-36074
Authentication headers exposed on by Nextcloud Server
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to account access exposure and compromise. It is recommended that the Nextcloud Server is upgraded to 23.0.7 or 24.0.3. It is recommended that the Nextcloud Enterprise Server is upgraded to 22.2.11, 23.0.7 or 24.0.3. There are no known workarounds for this issue.
Nextcloud server es un producto de nube personal de código abierto. Las versiones afectadas de este paquete son vulnerables a una Exposición de Información que falla al eliminar el encabezado de autorización en el descenso de HTTP. Esto puede conllevar a una exposición del acceso a la cuenta y su compromiso. Es recomendado actualizar el servidor Nextcloud a versión 23.0.7 o 24.0.3. Es recomendado que Nextcloud Enterprise Server sea actualizado a versión 22.2.11, 23.0.7 o 24.0.3. No se presentan mitigaciones conocidas para este problema
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-15 CVE Reserved
- 2022-09-15 CVE Published
- 2024-04-07 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-863: Incorrect Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vqgm-f748-g76v | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/nextcloud/server/pull/32941 | 2023-07-21 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Nextcloud Enterprise Server Search vendor "Nextcloud" for product "Nextcloud Enterprise Server" | < 22.2.11 Search vendor "Nextcloud" for product "Nextcloud Enterprise Server" and version " < 22.2.11" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Enterprise Server Search vendor "Nextcloud" for product "Nextcloud Enterprise Server" | >= 23.0.0 < 23.0.7 Search vendor "Nextcloud" for product "Nextcloud Enterprise Server" and version " >= 23.0.0 < 23.0.7" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Enterprise Server Search vendor "Nextcloud" for product "Nextcloud Enterprise Server" | >= 24.0.0 < 24.0.3 Search vendor "Nextcloud" for product "Nextcloud Enterprise Server" and version " >= 24.0.0 < 24.0.3" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | < 23.0.7 Search vendor "Nextcloud" for product "Nextcloud Server" and version " < 23.0.7" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 24.0.0 < 24.0.3 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 24.0.0 < 24.0.3" | - |
Affected
|