Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-39346


Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud Server is upgraded to 22.2.10, 23.0.7 or 24.0.3. There are no known workarounds for this issue.


Published

2022-11-25T19:15:11.623

Last Modified

2024-11-21T07:18:05.107

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.5 (LOW)

Weaknesses
  • Type: Primary
    CWE-20
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud nextcloud_enterprise_server < 22.2.10 Yes
Application nextcloud nextcloud_enterprise_server < 23.0.7 Yes
Application nextcloud nextcloud_enterprise_server < 24.0.3 Yes
Application nextcloud nextcloud_server < 22.2.10 Yes
Application nextcloud nextcloud_server < 23.0.7 Yes
Application nextcloud nextcloud_server < 24.0.3 Yes
Operating System fedoraproject fedora 35 Yes
Operating System fedoraproject fedora 36 Yes
Operating System fedoraproject fedora 37 Yes

References