CVE-2022-24741
High memory usage in Nextcloud server
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is recommended that the Nextcloud Server is upgraded to 21.0.8 , 22.2.4 or 23.0.1. Users unable to upgrade should disable preview generation with the `'enable_previews'` config flag.
El servidor Nextcloud es una plataforma de servicios de código abierto, de estilo de nube autoalojada. En las versiones afectadas, un atacante puede causar una denegación de servicio mediante la carga de archivos especialmente diseñados que harán que el servidor asigne demasiada memoria / CPU. Se recomienda actualizar el servidor Nextcloud a la versión 21.0.8 , 22.2.4 o 23.0.1. Los usuarios que no puedan actualizarse deberán desactivar la generación de vistas previas con la bandera de configuración `'enable_previews''
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-10 CVE Reserved
- 2022-03-09 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-10-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-jf3h-xf4q-mh89 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://hackerone.com/reports/1261225 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/nextcloud/server/pull/30291 | 2023-06-30 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202208-17 | 2023-06-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 21.0.0 < 21.0.8 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 21.0.0 < 21.0.8" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 22.0.0 < 22.2.4 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 22.0.0 < 22.2.4" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | 23.0.0 Search vendor "Nextcloud" for product "Nextcloud Server" and version "23.0.0" | - |
Affected
|