// For flags

CVE-2022-39364

Exception logging in Sharepoint app reveals clear-text connection details

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker reading `nextcloud.log` may gain knowledge of credentials to connect to a SharePoint service. Nextcloud Server versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server versions 22.2.10.5, 23.0.9, and 24.0.5 contain a patch for this issue. As a workaround, set `zend.exception_ignore_args = On` as an option in `php.ini`.

Nextcloud Server es el software de servidor de archivos para Nextcloud, una plataforma de productividad autohospedada. En Nextcloud Server anterior a las versiones 23.0.9 y 24.0.5 y Nextcloud Enterprise Server anterior a las versiones 22.2.10.5, 23.0.9 y 24.0.5, un atacante que lea `nextcloud.log` puede obtener conocimiento de las credenciales para conectarse al servicio de SharePoint. Las versiones 23.0.9 y 24.0.5 de Nextcloud Server y las versiones 22.2.10.5, 23.0.9 y 24.0.5 de Nextcloud Enterprise Server contienen un parche para este problema. Como workaround, configure `zend.exception_ignore_args = On` como una opciĆ³n en `php.ini`.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-09-02 CVE Reserved
  • 2022-10-27 CVE Published
  • 2024-05-19 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-312: Cleartext Storage of Sensitive Information
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nextcloud
Search vendor "Nextcloud"
Nextcloud Enterprise Server
Search vendor "Nextcloud" for product "Nextcloud Enterprise Server"
< 22.2.10.5
Search vendor "Nextcloud" for product "Nextcloud Enterprise Server" and version " < 22.2.10.5"
-
Affected
Nextcloud
Search vendor "Nextcloud"
Nextcloud Enterprise Server
Search vendor "Nextcloud" for product "Nextcloud Enterprise Server"
>= 23.0.0 < 23.0.9
Search vendor "Nextcloud" for product "Nextcloud Enterprise Server" and version " >= 23.0.0 < 23.0.9"
-
Affected
Nextcloud
Search vendor "Nextcloud"
Nextcloud Enterprise Server
Search vendor "Nextcloud" for product "Nextcloud Enterprise Server"
>= 24.0.0 < 24.0.5
Search vendor "Nextcloud" for product "Nextcloud Enterprise Server" and version " >= 24.0.0 < 24.0.5"
-
Affected
Nextcloud
Search vendor "Nextcloud"
Nextcloud Server
Search vendor "Nextcloud" for product "Nextcloud Server"
< 23.0.9
Search vendor "Nextcloud" for product "Nextcloud Server" and version " < 23.0.9"
-
Affected
Nextcloud
Search vendor "Nextcloud"
Nextcloud Server
Search vendor "Nextcloud" for product "Nextcloud Server"
>= 24.0.0 < 24.0.5
Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 24.0.0 < 24.0.5"
-
Affected