CVE-2022-39329 Information
Oct 28, 2022
cve
Description
Nextcloud Server is the file server software for Nextcloud a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.
Reference
https://hackerone.com/reports/1675014 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8f3p-rcm5-mrg3 https://github.com/nextcloud/server/pull/33643
Share on: