Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-39329


Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.


Published

2022-10-27T14:15:11.390

Last Modified

2024-11-21T07:18:03.057

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.5 (LOW)

Weaknesses
  • Type: Secondary
    CWE-284
    CWE-285
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud nextcloud_enterprise_server < 23.0.9 Yes
Application nextcloud nextcloud_enterprise_server < 24.0.5 Yes
Application nextcloud nextcloud_server < 23.0.9 Yes
Application nextcloud nextcloud_server < 24.0.5 Yes

References