CVE-2024-22400 LOW

CVE-2024-22400: Open redirect in user_saml via RelayState parameter in Nextcloud User Saml

Vendor Nextcloud
Product security-advisories
Weakness CWE-601 · Open redirect
Published January 18, 2024
Last update June 17, 2025

CVSS base score

3.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for this issue.

Key dates

02Disclosure timeline

January 18, 2024 CVE published
June 17, 2025 Record updated