CVE-2022-39330
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6 are vulnerable to a logged-in attacker slowing down the system by generating a lot of database/cpu load. Nextcloud Server versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server versions 22.2.10, 23.0.10, and 24.0.6 contain patches for this issue. As a workaround, disable the Circles app.
- Affected products
- Alt Linux, Circles, Nextcloud Enterprise Server, Nextcloud Server
- Nextcloud Nextcloud Enterprise Server
- < 22.2.10, 23.0.10, 24.0.6
- Nextcloud Nextcloud Server
- < 23.0.10, 24.0.6
- Fix
- Available
- CVSS 3.1
- 4.8 MEDIUM
- EPSS
- 0.8% (54th percentile)
- Weakness
- CWE-400
- NVD status
- Modified
- Published
- 2022-10-27
No indexed exploits for CVE-2022-39330 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-39330 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.