CVE-2022-39364 Information

Description

Nextcloud Server is the file server software for Nextcloud a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5 23.0.9 and 24.0.5 an attacker reading nextcloud.log may gain knowledge of credentials to connect to a SharePoint service. Nextcloud Server versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server versions 22.2.10.5 23.0.9 and 24.0.5 contain a patch for this issue. As a workaround set zend.exception_ignore_args = On as an option in php.ini.

Reference

https://github.com/nextcloud/sharepoint/issues/141 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qpf5-jj85-36h5 https://github.com/nextcloud/server/pull/33689 https://hackerone.com/reports/1652903

Share on: