Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the file zip app.
CVE ID: CVE-2024-22404
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.1
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Vendor: nextcloud
Product: security-advisories
EPSS Score: 0.45% (probability of being exploited)
EPSS Percentile: 62.5% (scored less or equal to compared to others)
EPSS Date: 2025-06-23 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false