PT-2022-16844 · Nextcloud+1 · Nextcloud Server+1

Fancycode

·

Published

2022-03-09

·

Updated

2023-06-30

·

CVE-2022-24741

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Nextcloud Server versions prior to 21.0.8 Nextcloud Server versions prior to 22.2.4 Nextcloud Server versions prior to 23.0.1
Description The issue affects Nextcloud server, an open source, self-hosted cloud style services platform. An attacker can cause a denial of service by uploading specially crafted files, which will cause the server to allocate too much memory or CPU.
Recommendations For versions prior to 21.0.8, upgrade to 21.0.8 or later. For versions prior to 22.2.4, upgrade to 22.2.4 or later. For versions prior to 23.0.1, upgrade to 23.0.1 or later. As a temporary workaround for users unable to upgrade, consider disabling preview generation with the enable previews config flag.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2504
ALT-PU-2022-2555
CVE-2022-24741
GHSA-JF3H-XF4Q-MH89

Affected Products

Alt Linux
Nextcloud Server