First published: Thu Oct 27 2022(Updated: )
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Enterprise Server | <23.0.9 | |
Nextcloud Nextcloud Enterprise Server | >=24.0.0<24.0.5 | |
Nextcloud Nextcloud Server | <23.0.9 | |
Nextcloud Nextcloud Server | >=24.0.0<24.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39329 is a vulnerability in Nextcloud Server and Nextcloud Enterprise Server that allows for exposure of information that cannot be controlled by administrators without direct database access.
CVE-2022-39329 affects Nextcloud Server and Nextcloud Enterprise Server versions 23.0.9 and 24.0.0 to 24.0.5, exposing information that administrators cannot control without direct database access.
CVE-2022-39329 has a severity rating of 5.3 (medium).
To fix CVE-2022-39329, users should upgrade to Nextcloud Server version 23.0.9 or Nextcloud Enterprise Server version 24.0.5 or later.
More information about CVE-2022-39329 can be found in the Nextcloud security advisories and related GitHub references.