ZeroHour

CVE-2022-41968

CVSS 3.1
5.3 medium
EPSS
<1%p56
Published
()
Modified
Description

Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5 contain patches for the issue. No known workarounds are available.

Vendors
nextcloud
Products
nextcloud server
Weakness
CWE-400, CWE-1284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.