PT-2022-19492 · Nextcloud+1 · Nextcloud Server+1
Demonia
·
Published
2022-05-31
·
Updated
2022-09-27
·
CVE-2022-29243
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Nextcloud Server versions prior to 22.2.7
Nextcloud Server versions prior to 23.0.4
Description
The issue is related to missing input-size validation of new session names in Nextcloud Server, allowing users to create app passwords with long names. These long names are then loaded into memory on usage, resulting in impacted performance.
Recommendations
For Nextcloud Server versions prior to 22.2.7, update to version 22.2.7 or later to resolve the issue.
For Nextcloud Server versions prior to 23.0.4, update to version 23.0.4 or later to resolve the issue.
Exploit
Fix
Resource Exhaustion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Nextcloud Server