CVE-2023-22470: Nextcloud Deck vulnerable to uncontrolled resource consumption
Published Jan 14, 2023
·Updated
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently no known workarounds. It is recommended that the Nextcloud Server is upgraded to 1.6.5 or 1.7.3 or 1.8.2.
Affected Software
3 affected components
Nextcloud Deck<1.6.5
Nextcloud Deck>=1.7.0<1.7.3
Nextcloud Deck>=1.8.0<1.8.2
Remediation
Patch Available
Event History
Jan 14, 2023
CVE Published
via MITRE·12:32 AM
Data Sourced
via MITRE·12:32 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-22470.
2
What is the severity level of CVE-2023-22470?
CVE-2023-22470 has a severity level of medium.
3
What is the affected software for CVE-2023-22470?
The affected software for CVE-2023-22470 is Nextcloud Deck versions 1.6.5 up to exclusive 1.8.2 (inclusive).
4
What is the impact of CVE-2023-22470?
CVE-2023-22470 can potentially cause a denial-of-service (DoS) when performed multiple times.
5
Are there any known workarounds for CVE-2023-22470?
There are currently no known workarounds for CVE-2023-22470.