CVE-2022-24741: High memory usage in Nextcloud server
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is recommended that the Nextcloud Server is upgraded to 21.0.8 , 22.2.4 or 23.0.1. Users unable to upgrade should disable preview generation with the 'enablepreviews' config flag.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24741?
CVE-2022-24741 is classified as a denial of service vulnerability.
How does CVE-2022-24741 exploit Nextcloud Server?
CVE-2022-24741 allows an attacker to upload specially crafted files, resulting in excessive memory or CPU usage.
Which versions of Nextcloud Server are affected by CVE-2022-24741?
CVE-2022-24741 affects Nextcloud Server versions from 21.0.0 to 21.0.8, and 22.0.0 to 22.2.4, as well as version 23.0.0.
How do I fix CVE-2022-24741?
To fix CVE-2022-24741, upgrade your Nextcloud Server to the latest patched version.
What impact does CVE-2022-24741 have on users?
The impact of CVE-2022-24741 includes potential service outages and degraded performance for users of the affected Nextcloud Server.