CVE-2024-22404

    Dashboard / Vulnerabilities / CVE-2024-22404

    CVE-2024-22404

    Published: 18 Jan 2024Last Modified: 12 Aug 2026

    Summary: Permissions bypass in Nextcloud with the files zip app

    Details: Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the file zip app.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 75c11bd4ba72a9b0175250746606b7ea79e5577b

    Affected versions

    1.4.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-22404 | CVE-DB