// For flags

CVE-2022-31120

Federated share accepting/declining is not logged in audit log in Nextcloud Server

Severity Score

2.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Nextcloud server is an open source personal cloud solution. The audit log is used to get a full trail of the actions which has been incompletely populated. In affected versions federated share events were not properly logged which would allow brute force attacks to go unnoticed. This behavior exacerbates the impact of CVE-2022-31118. It is recommended that the Nextcloud Server is upgraded to 22.2.7, 23.0.4 or 24.0.0. There are no workarounds available.

El servidor Nextcloud es una solución de nube personal de código abierto. El registro de auditoría se utiliza para obtener un rastro completo de las acciones que se ha poblado de forma incompleta. En las versiones afectadas, los eventos de uso compartido federado no se registraban correctamente, lo que permitía que los ataques de fuerza bruta pasaran desapercibidos. Este comportamiento exacerba el impacto de CVE-2022-31118. Se recomienda actualizar el servidor Nextcloud a la versión 22.2.7, 23.0.4 o 24.0.0. No hay soluciones disponibles

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-05-18 CVE Reserved
  • 2022-08-04 CVE Published
  • 2024-02-25 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-778: Insufficient Logging
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nextcloud
Search vendor "Nextcloud"
Nextcloud Server
Search vendor "Nextcloud" for product "Nextcloud Server"
< 22.2.7
Search vendor "Nextcloud" for product "Nextcloud Server" and version " < 22.2.7"
-
Affected
Nextcloud
Search vendor "Nextcloud"
Nextcloud Server
Search vendor "Nextcloud" for product "Nextcloud Server"
>= 23.0.0 < 23.0.4
Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 23.0.0 < 23.0.4"
-
Affected