CVE-2024-37313

Source
https://cve.org/CVERecord?id=CVE-2024-37313
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37313.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-37313
Aliases
  • GHSA-9v72-9xv5-3p7c
Published
2024-06-14T14:50:44Z
Modified
2026-08-12T03:51:27Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Nextcloud server allows the by-pass the second factor
Details

Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and Nextcloud Enterprise Server is upgraded to 21.0.9.17, 22.2.10.22, 23.0.12.17, 24.0.12.13, 25.0.13.8, 26.0.13, 27.1.8 or 28.0.4.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-287"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37313.json"
}
References

Affected packages

Git / github.com/nextcloud/server

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/server
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "26.0.0"
        },
        {
            "fixed": "26.0.13"
        },
        {
            "introduced": "27.0.0"
        },
        {
            "fixed": "27.1.8"
        },
        {
            "introduced": "28.0.0"
        },
        {
            "fixed": "28.0.4"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v26.*
v26.0.0
v26.0.1
v26.0.10
v26.0.10rc1
v26.0.11
v26.0.11rc1
v26.0.11rc2
v26.0.12
v26.0.12rc1
v26.0.12rc2
v26.0.13rc1
v26.0.1rc1
v26.0.2
v26.0.2rc1
v26.0.3
v26.0.3rc1
v26.0.3rc2
v26.0.4
v26.0.4rc1
v26.0.4rc2
v26.0.5
v26.0.5rc1
v26.0.6
v26.0.6rc1
v26.0.7
v26.0.8
v26.0.8rc1
v26.0.8rc2
v26.0.9
v26.0.9rc1
v27.*
v27.0.0
v27.0.1
v27.0.1rc1
v27.0.1rc2
v27.0.2
v27.0.2rc1
v27.1.0
v27.1.0beta2
v27.1.0beta3
v27.1.0rc1
v27.1.0rc2
v27.1.0rc3
v27.1.0rc4
v27.1.1
v27.1.2
v27.1.2rc1
v27.1.3
v27.1.3rc1
v27.1.3rc2
v27.1.4
v27.1.4rc1
v27.1.5
v27.1.5rc1
v27.1.6
v27.1.6rc1
v27.1.6rc2
v27.1.7
v27.1.7rc1
v27.1.7rc2
v27.1.8rc1
v28.*
v28.0.0
v28.0.1
v28.0.1rc1
v28.0.2
v28.0.2rc1
v28.0.2rc2
v28.0.2rc3
v28.0.2rc4
v28.0.2rc5
v28.0.3
v28.0.3rc1
v28.0.3rc2
v28.0.4rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37313.json"