CVE-2022-39329
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.
- Affected products
- Alt Linux, Nextcloud Enterprise Server, Nextcloud Server
- Nextcloud Nextcloud Enterprise Server
- < 23.0.9, 24.0.5
- Nextcloud Nextcloud Server
- < 23.0.9, 24.0.5
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 0.6% (45th percentile)
- Weakness
- CWE-862, CWE-284, CWE-285
- NVD status
- Modified
- Published
- 2022-10-27
CVE-2022-39329 at NVD
No indexed exploits for CVE-2022-39329 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-39329 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.