Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41968


Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5 contain patches for the issue. No known workarounds are available.


Published

2022-12-01T21:15:19.573

Last Modified

2024-11-21T07:24:10.513

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.5 (LOW)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    CWE-1284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud nextcloud_server < 23.0.10 Yes
Application nextcloud nextcloud_server < 23.0.10 Yes
Application nextcloud nextcloud_server < 24.0.5 Yes
Application nextcloud nextcloud_server < 24.0.5 Yes

References