Bug ID 1203190
Summary VUL-1: CVE-2022-35931: nextcloud: Password Policy app could generate passwords that would be block
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.5
Hardware Other
URL https://smash.suse.de/issue/341558/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter rfrohl@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2022-35931

Nextcloud Password Policy is an app that enables a Nextcloud server admin to
define certain rules for passwords. Prior to versions 22.2.10, 23.0.7, and
24.0.3 the random password generator may, in very rare cases, generate common
passwords that the validator itself would block. Upgrade Nextcloud Server to
22.2.10, 23.0.7 or 24.0.3 to receive a patch for the issue in Password Policy.
There are no known workarounds available.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-35931
https://www.cve.org/CVERecord?id=CVE-2022-35931
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-c7mw-9q4r-8qwr
https://github.com/nextcloud/password_policy/pull/363


You are receiving this mail because: