CVE-2022-31118

Nextcloud server is an open source personal cloud solution. In affected versions an attacker could brute force to find if federated sharing is being used and potentially try to brute force access tokens for federated shares (`a-zA-Z0-9` ^ 15). It is recommended that the Nextcloud Server is upgraded to 22.2.9, 23.0.6 or 24.0.2. Users unable to upgrade may disable federated sharing via the Admin Sharing settings in `index.php/settings/admin/sharing`.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-08-04 17:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-31118

Mitre link : CVE-2022-31118

CVE.ORG link : CVE-2022-31118


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts

CWE-770

Allocation of Resources Without Limits or Throttling