2.7

CVE-2022-35931

Nextcloud Password Policy's generated passwords are not fully validated by HIBPValidator

Generated passwords are not fully validated by HIBPValidator

Nextcloud Password Policy is an app that enables a Nextcloud server admin to define certain rules for passwords. Prior to versions 22.2.10, 23.0.7, and 24.0.3 the random password generator may, in very rare cases, generate common passwords that the validator itself would block. Upgrade Nextcloud Server to 22.2.10, 23.0.7 or 24.0.3 to receive a patch for the issue in Password Policy. There are no known workarounds available.
Mögliche Gegenmaßnahme
Password Policy: No workaround available
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudPassword Policy Version < 22.2.10
NextcloudPassword Policy Version >= 23.0.0 < 23.0.7
NextcloudPassword Policy Version >= 24.0.0 < 24.0.3
Weitere Schwachstelleninformationen
SystemNextcloud App
Produkt Password Policy
Version >= 0.0.0, < 22.2.10
Version >= 23.0.0, < 23.0.7
Version >= 24.0.0, < 24.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.459
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
security-advisories@github.com 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
CWE-261 Weak Encoding for Password

Obscuring a password with a trivial encoding does not protect the password.

CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.