CVE-2022-39330
27.10.2022, 14:15
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6 are vulnerable to a logged-in attacker slowing down the system by generating a lot of database/cpu load. Nextcloud Server versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server versions 22.2.10, 23.0.10, and 24.0.6 contain patches for this issue. As a workaround, disable the Circles app.Enginsight
Vendor | Product | Version |
---|---|---|
nextcloud | nextcloud_enterprise_server | 𝑥 < 22.2.10 |
nextcloud | nextcloud_enterprise_server | 23.0.0 ≤ 𝑥 < 23.0.10 |
nextcloud | nextcloud_enterprise_server | 24.0.0 ≤ 𝑥 < 24.0.6 |
nextcloud | nextcloud_server | 𝑥 < 23.0.10 |
nextcloud | nextcloud_server | 24.0.0 ≤ 𝑥 < 24.0.6 |
𝑥
= Vulnerable software versions
References