← Back

CVE-2022-39346

nvd nist
Published: Nov 25, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud Server is upgraded to 22.2.10, 23.0.7 or 24.0.3. There are no known workarounds for this issue.

Affected (9)

2 products
Nextcloud Enterprise Server
Nextcloud Server
1 product
Fedora
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
Before 22.2.10
From 23.0.0 to 23.0.7
From 24.0.0 to 24.0.3
Nextcloud
Before 22.2.10
From 23.0.0 to 23.0.7
From 24.0.0 to 24.0.3
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36
Version 37

References (12)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Permissions RequiredThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredThird Party Advisory

Timeline

No history available yet.