CVE-2022-39329
Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access.
Does this matter?
Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.65% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-285, CWE-862
- Affected
- nextcloud/nextcloud enterprise server · nextcloud/nextcloud server
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8f3p-rcm5-mrg3Third Party Advisory
- https://github.com/nextcloud/server/pull/33643Patch, Third Party Advisory
- https://hackerone.com/reports/1675014Permissions Required, Third Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8f3p-rcm5-mrg3Third Party Advisory
- https://github.com/nextcloud/server/pull/33643Patch, Third Party Advisory
- https://hackerone.com/reports/1675014Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.