← volver
CVE-2022-39211

Server-Side Request Forgery (SSRF) via potential filter bypass in Nextcloud Server

CVSS 3 LOWEPSS 0.7%CWE-918
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 3EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
16 sep 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webservices can be found and requested erroneously. It is recommended that the Nextcloud Server is upgraded to 23.0.8 or 24.0.4. It is recommended that the Nextcloud Enterprise Server is upgraded to 22.2.10.4, 23.0.8 or 24.0.4. There are no known workarounds for this issue.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →