HIGH🇵🇱 Wersja polska

CVE-2024-37313

CVSS 7.3v3.1pub. 2024-06-14upd. 2025-09-26

Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and Nextcloud Enterprise Server is upgraded to 21.0.9.17, 22.2.10.22, 23.0.12.17, 24.0.12.13, 25.0.13.8, 26.0.13, 27.1.8 or 28.0.4.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • Nextcloud Server

    APP
    Nextcloud
    21.0.0 – 21.0.9.17 (excl.)22.0.0 – 22.2.10.22 (excl.)23.0.0 – 23.0.12.17 (excl.)24.0.0 – 24.0.12.13 (excl.)25.0.0 – 25.0.13.8 (excl.)26.0.0 – 26.0.13 (excl.)27.0.0 – 27.1.8 (excl.)28.0.0 – 28.0.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-26482CRITICAL9.0PL ✓same product

Nextcloud Server: brak walidacji scope umożliwia RCE przez workflow

CVE-2021-32802CRITICAL9.3PL ✓same product

Nextcloud Server — SSRF, ujawnienie plików lub RCE przez podglądy obrazów

CVE-2021-22915CRITICAL9.8PL ✓same product

Nextcloud Server — obejście ochrony brute-force przez adresy IPv6

CVE-2026-45281HIGH8.1same product

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before...

CVE-2024-37882HIGH8.1same product

Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions co...