CVE-2022-29243: Improper input-size validation on the user new session name in Nextcloud Server
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.7 and 23.0.4, missing input-size validation of new session names allows users to create app passwords with long names. These long names are then loaded into memory on usage, resulting in impacted performance. Versions 22.2.7 and 23.0.4 contain a fix for this issue. There are currently no known workarounds available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-29243?
CVE-2022-29243 is a vulnerability in Nextcloud Server that allows users to create app passwords with long names, which can result in excessive memory usage.
What is the severity of CVE-2022-29243?
The severity of CVE-2022-29243 is medium, with a CVSS score of 4.3.
How does CVE-2022-29243 affect Nextcloud Server?
CVE-2022-29243 affects Nextcloud Server versions up to 22.2.7 and versions up to 23.0.4.
Is there a fix for CVE-2022-29243?
Yes, the fix for CVE-2022-29243 is included in Nextcloud Server versions 22.2.7 and 23.0.4.
Where can I find more information about CVE-2022-29243?
You can find more information about CVE-2022-29243 on the Nextcloud security advisories page, the Nextcloud Server pull request, and the HackerOne report.