Nextcloud: Attackers can bypass two-factor authentication
The cloud service software Nextcloud is vulnerable. The developers have closed several security gaps in current versions.
If you operate your own cloud with Nextcloud, you should update your server. Otherwise, attacks are possible and attackers can gain access.
Several software vulnerabilities
The cloud software provider has closed a total of twelve security vulnerabilities. In addition to Nextcloud Server and Nextcloud Enterprise Server, certain components such as the calendar are also at risk.
The majority of vulnerabilities are classified as"medium" threat level. After successful attacks, attackers can manipulate calendar entries and direct victims to a website they control, among other things.
Two vulnerabilities in Nextcloud and Nextcloud Enterprise are considered the most dangerous. At these points, attackers can extend the rights of shares (CVE-2024-37882"high") or bypass two-factor authentication (CVE-2024-37313"high"). The developers do not currently specify how such attacks could take place.
Because a list of the threatened and repaired versions would go beyond the scope of this message, admins must read this information in the linked warning posts.
List sorted by threat level in descending order:
- Nextcloud, Nextcloud Enterprise Server: Can reshare read&share only folder with more permissions
- Nextcloud, Nextcloud Enterprise Server: Ability to by-pass second factor
- Nextcloud user_oidc: ID4me feature of OpenID connect app available even when disabled
- Nextcloud user_oidc: ID4me does not validate signature or expiration
- Nextcloud Calendar: Event create can create attachments that link to other websites
- Nextcloud Notes: Notes app can be tricked into using a received share created before the user logged in
- Nextcloud Deck: Can access comments and attachments of deleted cards
- Nextcloud Desktop clinet macOS: Code injection in Nextcloud Desktop Client for macOS
- Nextcloud Photos: Missing permission check when removing a photo from an album
- Nextcloud Nextcloud Enterprise Server: Read-only users can restore old versions
- Nextcloud Nextcloud Enterprise Server: Users can delete old versions of read-only shared files
- Nextcloud Nextcloud Enterprise Server: Events information leaked with shared calendars on recurrence exceptions
(des)