CVE-2022-41968 Information
Dec 02, 2022
cve
Description
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5 calendar name lengths are not validated before writing to a database. As a result an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5 contain patches for the issue. No known workarounds are available.
Reference
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m92j-xxc8-hq3v https://hackerone.com/reports/1596148 https://github.com/nextcloud/server/pull/33139
Share on: