Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22404


Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the file zip app.


Published

2024-01-18T21:15:08.830

Last Modified

2024-11-21T08:56:12.947

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-281

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud zipper < 1.2.1 Yes
Application nextcloud zipper 1.4.0 Yes

References