CVE-2022-39364: Exception logging in Sharepoint app reveals clear-text connection details
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker reading nextcloud.log may gain knowledge of credentials to connect to a SharePoint service. Nextcloud Server versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server versions 22.2.10.5, 23.0.9, and 24.0.5 contain a patch for this issue. As a workaround, set zend.exceptionignoreargs = On as an option in php.ini.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-39364?
CVE-2022-39364 refers to a vulnerability in Nextcloud Server and Nextcloud Enterprise Server that allows an attacker reading nextcloud.log to gain knowledge of credentials.
What is the severity of CVE-2022-39364?
CVE-2022-39364 has a severity rating of 6.5 (medium).
Which versions of Nextcloud Server and Nextcloud Enterprise Server are affected by CVE-2022-39364?
CVE-2022-39364 affects Nextcloud Server versions up to 23.0.9 and Nextcloud Enterprise Server versions up to 22.2.10.5, 23.0.9, and 24.0.5.
How can an attacker exploit CVE-2022-39364?
An attacker can exploit CVE-2022-39364 by reading nextcloud.log to gain knowledge of credentials.
Are there any references for CVE-2022-39364?
Yes, you can find references for CVE-2022-39364 on the Nextcloud Security Advisories page and the Nextcloud Server GitHub repository.