Nextcloud Enterprise Server vulnerabilities
6 known vulnerabilities affecting nextcloud/nextcloud_enterprise_server.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2022-39346MEDIUMCVSS 6.5fixed in 22.2.10≥ 23.0.0, < 23.0.7+1 more2022-11-25
CVE-2022-39346 [MEDIUM] CWE-20 CVE-2022-39346: Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did
Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud Server is upgraded to 22.2.10, 23.0.7 or 24.0.3. There are no known workaround
nvd
CVE-2022-39364MEDIUMCVSS 6.5fixed in 22.2.10.5≥ 23.0.0, < 23.0.9+1 more2022-10-27
CVE-2022-39364 [MEDIUM] CWE-312 CVE-2022-39364: Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker reading `nextcloud.log` may gain knowledge of credentials to connect to a SharePoint service. Nextcloud Ser
nvd
CVE-2022-39329MEDIUMCVSS 5.3fixed in 23.0.9≥ 24.0.0, < 24.0.52022-10-27
CVE-2022-39329 [MEDIUM] CWE-284 CVE-2022-39329: Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nex
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for thi
nvd
CVE-2022-39330MEDIUMCVSS 4.3fixed in 22.2.10≥ 23.0.0, < 23.0.10+1 more2022-10-27
CVE-2022-39330 [MEDIUM] CWE-400 CVE-2022-39330: Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nex
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6 are vulnerable to a logged-in attacker slowing down the system by generating a lot of database/cpu load. Nextcloud Server
nvd
CVE-2022-39211MEDIUMCVSS 5.3fixed in 22.2.10.4≥ 23.0.0, < 23.0.8+1 more2022-09-16
CVE-2022-39211 [MEDIUM] CWE-918 CVE-2022-39211: Nextcloud server is an open source personal cloud platform. In affected versions it was found that l
Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webservices can be found and requested erroneously. It is recommended that the Nextcloud Server is upgraded to 23.0.8 or 24.0.4. It is recommended that the Nextcloud Enterprise Server is upgraded to 22.2.10.4, 23.0.8 or 24.0.4. There ar
nvd
CVE-2022-36074HIGHCVSS 7.5fixed in 22.2.11≥ 23.0.0, < 23.0.7+1 more2022-09-15
CVE-2022-36074 [HIGH] CWE-200 CVE-2022-36074: Nextcloud server is an open source personal cloud product. Affected versions of this package are vul
Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to account access exposure and compromise. It is recommended that the Nextcloud Server is upgraded to 23.0.7 or 24.0.3. It is recommended that
nvd