CVE-2022-41968

LOW

Nextcloud Server < 23.0.10 - Denial of Service

Title source: rule
STIX 2.1

Description

Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5 contain patches for the issue. No known workarounds are available.

Scores

CVSS v3 3.5
EPSS 0.0029
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1284 CWE-400
Status published
Products (1)
nextcloud/nextcloud_server 23.0.0 - 23.0.10 (2 CPE variants)
Published Dec 01, 2022
Tracked Since Feb 18, 2026