CVE-2022-39346

LOW

Nextcloud Server < 22.2.10 - Denial of Service via Uncontrolled Display Name Length

Title source: llm
STIX 2.1

Description

Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud Server is upgraded to 22.2.10, 23.0.7 or 24.0.3. There are no known workarounds for this issue.

Scores

CVSS v3 3.5
EPSS 0.0227
EPSS Percentile 84.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400 CWE-20
Status published
Products (5)
fedoraproject/fedora 35
fedoraproject/fedora 36
fedoraproject/fedora 37
nextcloud/nextcloud_enterprise_server < 22.2.10
nextcloud/nextcloud_server < 22.2.10
Published Nov 25, 2022
Tracked Since Feb 18, 2026