CyberzSOC

Publication detail
← Back to advisories & guidance

2024-061: Vulnerabilities in Nextcloud Products ↗ source

June 18, 2024 CERT-EU Advisory

Summary

A vulnerability was disclosed in Nextcloud server products that allows the bypassing of the second factor of two-factor authentication (2FA) [1,2]. The vulnerability CVE-2024-37313, with a CVSS score of 7.3, is a 2FA bypass issue. Under certain circumstances, an attacker could exploit this vulnerability to bypass the second factor of 2FA after successfully providing the user credentials [1]. Patched versions of the products are listed below [1,3]. 25.0.13.8, 26.0.13, 27.1.8 and 28.0.4. CERT-EU strongly recommends updating affected software to the latest versions by following the instructions given by the vendor [1].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-37313 7.3 High nextcloud security-advisories Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfull…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.