CVE-2022-24888
The server rejects files and folders that have these characters in the middle of their names, so this might be an opportunity for injection.
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1, it is possible to create files and folders that have leading and trailing \n, \r, \t, and \v characters. The server rejects files and folders that have these characters in the middle of their names, so this might be an opportunity for injection. This issue is fixed in versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1. There are currently no known workarounds.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- nextcloud/nextcloud server
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-w3h6-p64h-q9jpThird Party Advisory
- https://github.com/nextcloud/server/pull/29895Patch, Third Party Advisory
- https://hackerone.com/reports/1402249Permissions Required, Third Party Advisory
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-w3h6-p64h-q9jpThird Party Advisory
- https://github.com/nextcloud/server/pull/29895Patch, Third Party Advisory
- https://hackerone.com/reports/1402249Permissions Required, Third Party Advisory
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.