SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-39346

Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service.

MEDIUM 6.5EPSS 1.04%

Does this matter?

Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.

Description

Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud Server is upgraded to 22.2.10, 23.0.7 or 24.0.3. There are no known workarounds for this issue.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
1.04% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-400
Affected
nextcloud/nextcloud enterprise server · nextcloud/nextcloud server · fedoraproject/fedora
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.