CVE-2022-31118

Nextcloud server is an open source personal cloud solution. In affected versions an attacker could brute force to find if federated sharing is being used and potentially try to brute force access tokens for federated shares (`a-zA-Z0-9` ^ 15). It is recommended that the Nextcloud Server is upgraded to 22.2.9, 23.0.6 or 24.0.2. Users unable to upgrade may disable federated sharing via the Admin Sharing settings in `index.php/settings/admin/sharing`.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*

History

10 Aug 2022, 15:31

Type Values Removed Values Added
References (MISC) https://github.com/nextcloud/server/pull/32843/commits/6eb692da7fe73c899cb6a8d2aa045eddb1f14018 - (MISC) https://github.com/nextcloud/server/pull/32843/commits/6eb692da7fe73c899cb6a8d2aa045eddb1f14018 - Patch, Third Party Advisory
References (CONFIRM) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vwh-5v93-3vcq - (CONFIRM) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vwh-5v93-3vcq - Third Party Advisory
CWE CWE-770 CWE-307
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Nextcloud nextcloud Server
Nextcloud
CPE cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*

04 Aug 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-04 17:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-31118

Mitre link : CVE-2022-31118

CVE.ORG link : CVE-2022-31118


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts

CWE-770

Allocation of Resources Without Limits or Throttling