CVE-2022-41968
Nextcloud Server's calendar name length not validated before writing to database
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5 contain patches for the issue. No known workarounds are available.
Nextcloud Server es un servidor en la nube personal de código abierto. Antes de las versiones 23.0.10 y 24.0.5, las longitudes de los nombres del calendario no se validan antes de escribir en una base de datos. Como resultado, un atacante puede enviar cantidades innecesarias de datos a la base de datos. Las versiones 23.0.10 y 24.0.5 contienen parches para el problema. No hay workarounds disponibles.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-30 CVE Reserved
- 2022-12-01 CVE Published
- 2024-06-23 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-1284: Improper Validation of Specified Quantity in Input
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m92j-xxc8-hq3v | Third Party Advisory | |
https://hackerone.com/reports/1596148 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/nextcloud/server/pull/33139 | 2023-07-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 23.0.0 < 23.0.10 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 23.0.0 < 23.0.10" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 23.0.0 < 23.0.10 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 23.0.0 < 23.0.10" | enterprise |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 24.0.0 < 24.0.5 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 24.0.0 < 24.0.5" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 24.0.0 < 24.0.5 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 24.0.0 < 24.0.5" | enterprise |
Affected
|