6.5

CVE-2022-39346

Missing length validation of user displayname in nextcloud server

Missing length validation of user displayname allows to generate an SQL error

Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud Server is upgraded to 22.2.10, 23.0.7 or 24.0.3. There are no known workarounds for this issue.
Mögliche Gegenmaßnahme
Server: No workaround available
Enterprise Server: No workaround available
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudNextcloud Enterprise Server Version < 22.2.10
NextcloudNextcloud Enterprise Server Version >= 23.0.0 < 23.0.7
NextcloudNextcloud Enterprise Server Version >= 24.0.0 < 24.0.3
NextcloudNextcloud Server Version < 22.2.10
NextcloudNextcloud Server Version >= 23.0.0 < 23.0.7
NextcloudNextcloud Server Version >= 24.0.0 < 24.0.3
FedoraprojectFedora Version35
FedoraprojectFedora Version36
FedoraprojectFedora Version37
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemNextcloud
Produkt Server
Version >= 0.0.0, < 22.2.10
Version >= 23.0.0, < 23.0.7
Version >= 24.0.0, < 24.0.3
SystemNextcloud
Produkt Enterprise Server
Version >= 0.0.0, < 22.2.10
Version >= 23.0.0, < 23.0.7
Version >= 24.0.0, < 24.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.6% 0.817
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
security-advisories@github.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.