Improper handling of request URLs in Guests app allows guest users to bypass app allowlist
Package
Guests
(Nextcloud)
Affected versions
>= 2.4.0, >= 2.5.0, >= 3.0.0
Patched versions
2.4.1, 2.5.1, 3.0.1
Impact
Users were able to load the pages of apps they were actually not allowed to access.
Patches
It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1
Workarounds
References
For more information
If you have any questions or comments about this advisory: