CVE-2022-41968

Source
https://cve.org/CVERecord?id=CVE-2022-41968
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41968.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-41968
Aliases
  • GHSA-m92j-xxc8-hq3v
Published
2022-12-01T20:38:46.973Z
Modified
2026-08-12T03:51:12.045257901Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Nextcloud Server's calendar name length not validated before writing to database
Details

Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5 contain patches for the issue. No known workarounds are available.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41968.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nextcloud/server

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/server
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "23.0.0"
        },
        {
            "fixed": "23.0.10"
        },
        {
            "introduced": "24.0.0"
        },
        {
            "fixed": "24.0.5"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v23.*
v23.0.0
v23.0.1
v23.0.10rc1
v23.0.1rc1
v23.0.1rc2
v23.0.1rc3
v23.0.2
v23.0.2rc1
v23.0.3
v23.0.3rc1
v23.0.3rc2
v23.0.4
v23.0.4rc1
v23.0.5
v23.0.5rc1
v23.0.6
v23.0.6rc1
v23.0.7
v23.0.7rc1
v23.0.7rc2
v23.0.8
v23.0.8rc1
v23.0.9
v23.0.9rc1
v24.*
v24.0.0
v24.0.1
v24.0.1rc1
v24.0.2
v24.0.2rc1
v24.0.3
v24.0.3rc1
v24.0.3rc2
v24.0.4
v24.0.4rc1
v24.0.5rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41968.json"