CVE-2022-36074 MEDIUM

CVE-2022-36074: Authentication headers exposed on by Nextcloud Server

Vendor Nextcloud
Product security-advisories
Weakness CWE-200 · Info exposure
Published September 15, 2022
Last update April 23, 2025

CVSS base score

6.4/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to account access exposure and compromise. It is recommended that the Nextcloud Server is upgraded to 23.0.7 or 24.0.3. It is recommended that the Nextcloud Enterprise Server is upgraded to 22.2.11, 23.0.7 or 24.0.3. There are no known workarounds for this issue.

Key dates

02Disclosure timeline

September 15, 2022 CVE published
April 23, 2025 Record updated