Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5 contain patches for the issue. No known workarounds are available.
The product does not properly control the allocation and maintenance of a limited resource.
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Link | Tags |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m92j-xxc8-hq3v | third party advisory |
https://github.com/nextcloud/server/pull/33139 | third party advisory patch |
https://hackerone.com/reports/1596148 | third party advisory |