MEDIUM
Nextcloud Server's calendar name length not validated before writing to database
Published Dec 1, 2022
5.3
MEDIUMCVSS 3.1
EPSS 0.92%
Description
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5 contain patches for the issue. No known workarounds are available.
Affected products
-
- Version < 23.0.10StatusaffectedConstraints-
- Version >= 24.0.0, < 24.0.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Nextcloud | Security-Advisories | n/a |
|
OR
- ≥ 23.0.0 · < 23.0.10
- ≥ 23.0.0 · < 23.0.10
- ≥ 24.0.0 · < 24.0.5
- ≥ 24.0.0 · < 24.0.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-45072 Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m92j-xxc8-hq3v x_refsource_CONFIRMThird Party Advisory
- https://github.com/nextcloud/server/pull/33139 x_refsource_MISCPatchThird Party Advisory
- https://hackerone.com/reports/1596148 x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-45072 | Advisory | |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m92j-xxc8-hq3v | x_refsource_CONFIRMThird Party Advisory | |
| https://github.com/nextcloud/server/pull/33139 | x_refsource_MISCPatchThird Party Advisory | |
| https://hackerone.com/reports/1596148 | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Dec 1, 2022
Updated Apr 23, 2025
Reserved Sep 30, 2022
Link CVE-2022-41968
CISA Vulnrichment
Updated Apr 23, 2025
ENISA EUVD
EUVD-2022-45072 Assigner GitHub_M
Published Dec 1, 2022
Updated Apr 23, 2025
Exploited since n/a
Link EUVD-2022-45072