CVE-2023-22470

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently no known workarounds. It is recommended that the Nextcloud Server is upgraded to 1.6.5 or 1.7.3 or 1.8.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*

History

24 Jan 2023, 01:29

Type Values Removed Values Added
References (MISC) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-93j5-wx4c-6g88 - (MISC) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-93j5-wx4c-6g88 - Third Party Advisory
References (MISC) https://github.com/nextcloud/deck/pull/4059 - (MISC) https://github.com/nextcloud/deck/pull/4059 - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-400 CWE-20
First Time Nextcloud
Nextcloud deck
CPE cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*

14 Jan 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-14 01:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-22470

Mitre link : CVE-2023-22470

CVE.ORG link : CVE-2023-22470


JSON object : View

Products Affected

nextcloud

  • deck
CWE
CWE-20

Improper Input Validation

CWE-400

Uncontrolled Resource Consumption