ZeroHour

CVE-2022-39329

CVSS 3.1
5.3 medium
EPSS
<1%p49
Published
()
Modified
Description

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.

Vendors
nextcloud
Products
nextcloud enterprise server, nextcloud server
Weakness
CWE-284, CWE-285, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.