CVE-2022-31118

Nextcloud server is an open source personal cloud solution. In affected versions an attacker could brute force to find if federated sharing is being used and potentially try to brute force access tokens for federated shares (`a-zA-Z0-9` ^ 15). It is recommended that the Nextcloud Server is upgraded to 22.2.9, 23.0.6 or 24.0.2. Users unable to upgrade may disable federated sharing via the Admin Sharing settings in `index.php/settings/admin/sharing`.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:03

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vwh-5v93-3vcq - Third Party Advisory () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vwh-5v93-3vcq - Third Party Advisory
References () https://github.com/nextcloud/server/pull/32843/commits/6eb692da7fe73c899cb6a8d2aa045eddb1f14018 - Patch, Third Party Advisory () https://github.com/nextcloud/server/pull/32843/commits/6eb692da7fe73c899cb6a8d2aa045eddb1f14018 - Patch, Third Party Advisory

10 Aug 2022, 15:31

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-770 CWE-307
CPE cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
References (MISC) https://github.com/nextcloud/server/pull/32843/commits/6eb692da7fe73c899cb6a8d2aa045eddb1f14018 - (MISC) https://github.com/nextcloud/server/pull/32843/commits/6eb692da7fe73c899cb6a8d2aa045eddb1f14018 - Patch, Third Party Advisory
References (CONFIRM) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vwh-5v93-3vcq - (CONFIRM) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vwh-5v93-3vcq - Third Party Advisory

04 Aug 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-04 17:15

Updated : 2024-11-21 07:03


NVD link : CVE-2022-31118

Mitre link : CVE-2022-31118

CVE.ORG link : CVE-2022-31118


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-307

Improper Restriction of Excessive Authentication Attempts