CVE-2022-39211 LOW

CVE-2022-39211: Server-Side Request Forgery (SSRF) via potential filter bypass in Nextcloud Server

Vendor Nextcloud
Product security-advisories
Weakness CWE-918 · SSRF
Published September 16, 2022
Last update April 23, 2025

CVSS base score

3.0/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webservices can be found and requested erroneously. It is recommended that the Nextcloud Server is upgraded to 23.0.8 or 24.0.4. It is recommended that the Nextcloud Enterprise Server is upgraded to 22.2.10.4, 23.0.8 or 24.0.4. There are no known workarounds for this issue.

Key dates

02Disclosure timeline

September 16, 2022 CVE published
April 23, 2025 Record updated