First published: Tue Sep 06 2022(Updated: )
Nextcloud Password Policy is an app that enables a Nextcloud server admin to define certain rules for passwords. Prior to versions 22.2.10, 23.0.7, and 24.0.3 the random password generator may, in very rare cases, generate common passwords that the validator itself would block. Upgrade Nextcloud Server to 22.2.10, 23.0.7 or 24.0.3 to receive a patch for the issue in Password Policy. There are no known workarounds available.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Password Policy | <22.2.10 | |
Nextcloud Password Policy | >=23.0.0<23.0.7 | |
Nextcloud Password Policy | >=24.0.0<24.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35931 has a low severity rating as it involves the random password generator producing potentially common passwords.
To fix CVE-2022-35931, upgrade to Nextcloud Password Policy version 22.2.10, 23.0.7, or 24.0.3 or later.
Versions of Nextcloud Password Policy prior to 22.2.10, 23.0.7, and 24.0.3 are affected by CVE-2022-35931.
CVE-2022-35931 can result in the generation of passwords that may inadvertently be common and thus weakened security.
There is no official workaround for CVE-2022-35931, and it is recommended to upgrade to a patched version.