CVE-2022-39329: Profile of disabled user stays accessible
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-39329?
CVE-2022-39329 is a vulnerability in Nextcloud Server and Nextcloud Enterprise Server that allows for exposure of information that cannot be controlled by administrators without direct database access.
How does CVE-2022-39329 affect Nextcloud's file server software?
CVE-2022-39329 affects Nextcloud Server and Nextcloud Enterprise Server versions 23.0.9 and 24.0.0 to 24.0.5, exposing information that administrators cannot control without direct database access.
What is the severity of CVE-2022-39329?
CVE-2022-39329 has a severity rating of 5.3 (medium).
How can I fix CVE-2022-39329?
To fix CVE-2022-39329, users should upgrade to Nextcloud Server version 23.0.9 or Nextcloud Enterprise Server version 24.0.5 or later.
Where can I find more information about CVE-2022-39329?
More information about CVE-2022-39329 can be found in the Nextcloud security advisories and related GitHub references.