SB2022080525 - Information disclosure in Nextcloud Server
Published: August 5, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2022-31118)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to missing brute force protection on cloud federation sharing. A remote attacker can perform a brute force attack to find if federated sharing is being used and potentially try to brute force access tokens for federated shares.
Remediation
Install update from vendor's website.