Vulnerability record · CVE-2024-22403 · published 18 January 2024
CVE-2024-22403: Nextcloud server insufficient session expiration vulnerability
Nextcloud · Nextcloud Server
Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are invalidated after 10 minutes and will no longer be authenticated. To exploit this vulnerability an attacker would need to intercept an OAuth code from a user session. It is recommended that the Nextcloud Server is upgraded to 28.0.0. There are no known workarounds for this vulnerability.
Description
Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are invalidated after 10 minutes and will no longer be authenticated. To exploit this vulnerability an attacker would need to intercept an OAuth code from a user session. It is recommended that the Nextcloud Server is upgraded to 28.0.0. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wppc-f5g8-vx36 | Vendor Advisory |
| https://github.com/nextcloud/server/pull/40766 | PatchVendor Advisory |
| https://hackerone.com/reports/1784162 | Permissions RequiredThird Party Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/S6PN4GVJ5TZUC6WSG4X3ZA3AM | |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wppc-f5g8-vx36 | Vendor Advisory |
| https://github.com/nextcloud/server/pull/40766 | PatchVendor Advisory |
| https://hackerone.com/reports/1784162 | Permissions RequiredThird Party Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/S6PN4GVJ5TZUC6WSG4X3ZA3AM |
Track CVE-2024-22403 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-22403), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.