CVE-2022-39330: Database resource exhaustion for logged-in users via sharee recommendations with circles
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6 are vulnerable to a logged-in attacker slowing down the system by generating a lot of database/cpu load. Nextcloud Server versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server versions 22.2.10, 23.0.10, and 24.0.6 contain patches for this issue. As a workaround, disable the Circles app.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-39330?
CVE-2022-39330 is a vulnerability in Nextcloud Server and Nextcloud Enterprise Server that allows a logged-in attacker to slow down the system.
How does CVE-2022-39330 affect Nextcloud Server?
CVE-2022-39330 affects Nextcloud Server prior to versions 23.0.10 and 24.0.6.
How does CVE-2022-39330 affect Nextcloud Enterprise Server?
CVE-2022-39330 affects Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6.
What is the severity of CVE-2022-39330?
CVE-2022-39330 has a severity level of medium.
How can I fix CVE-2022-39330?
To fix CVE-2022-39330, you should update Nextcloud Server to versions 23.0.10 or 24.0.6, and Nextcloud Enterprise Server to versions 22.2.10, 23.0.10, or 24.0.6.