CVE-2022-31118

Nextcloud server is an open source personal cloud solution. In affected versions an attacker could brute force to find if federated sharing is being used and potentially try to brute force access tokens for federated shares (`a-zA-Z0-9` ^ 15). It is recommended that the Nextcloud Server is upgraded to 22.2.9, 23.0.6 or 24.0.2. Users unable to upgrade may disable federated sharing via the Admin Sharing settings in `index.php/settings/admin/sharing`.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:03

Type Values Removed Values Added
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vwh-5v93-3vcq - Third Party Advisory () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vwh-5v93-3vcq - Third Party Advisory
References () https://github.com/nextcloud/server/pull/32843/commits/6eb692da7fe73c899cb6a8d2aa045eddb1f14018 - Patch, Third Party Advisory () https://github.com/nextcloud/server/pull/32843/commits/6eb692da7fe73c899cb6a8d2aa045eddb1f14018 - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5

Information

Published : 2022-08-04 17:15

Updated : 2024-11-21 07:03


NVD link : CVE-2022-31118

Mitre link : CVE-2022-31118

CVE.ORG link : CVE-2022-31118


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-307

Improper Restriction of Excessive Authentication Attempts