CVE Vulnerabilities

CVE-2024-37313

Improper Authentication

Published: Jun 14, 2024 | Modified: Sep 26, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and Nextcloud Enterprise Server is upgraded to 21.0.9.17, 22.2.10.22, 23.0.12.17, 24.0.12.13, 25.0.13.8, 26.0.13, 27.1.8 or 28.0.4.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Nextcloud_server Nextcloud 21.0.0 (including) 21.0.9.17 (excluding)
Nextcloud_server Nextcloud 22.0.0 (including) 22.2.10.22 (excluding)
Nextcloud_server Nextcloud 23.0.0 (including) 23.0.12.17 (excluding)
Nextcloud_server Nextcloud 24.0.0 (including) 24.0.12.13 (excluding)
Nextcloud_server Nextcloud 25.0.0 (including) 25.0.13.8 (excluding)
Nextcloud_server Nextcloud 26.0.0 (including) 26.0.13 (excluding)
Nextcloud_server Nextcloud 27.0.0 (including) 27.1.8 (excluding)
Nextcloud_server Nextcloud 28.0.0 (including) 28.0.4 (excluding)

Potential Mitigations

References