Bug ID 1205802
Summary VUL-0: CVE-2022-39346: nextcloud: Missing length validation of user displayname allows to generate an SQL error
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/348950/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee ecsos@schirra.net
Reporter cathy.hu@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

rh#2148815

Nextcloud server is an open source personal cloud server. Affected versions of
nextcloud server did not properly limit user display names which could allow a
malicious users to overload the backing database and cause a denial of service.
It is recommended that the Nextcloud Server is upgraded to 22.2.10, 23.0.7 or
24.0.3. There are no known workarounds for this issue.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6w9f-jgjx-4vj6
https://github.com/nextcloud/server/pull/33052
https://hackerone.com/reports/1588562

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2148815
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39346
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6w9f-jgjx-4vj6
http://www.cvedetails.com/cve/CVE-2022-39346/
https://github.com/nextcloud/server/pull/33052
https://www.cve.org/CVERecord?id=CVE-2022-39346
https://hackerone.com/reports/1588562


You are receiving this mail because: