CVE Feed

    Dashboard / CVE / CVE-2022-24741

    CVE-2022-24741

    Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is recommended that the Nextcloud Server is upgraded to 21.0.8 , 22.2.4 or 23.0.1. Users unable to upgrade should disable preview generation with the `'enable_previews'` config flag.

    Published:Mar 9, 2022
    Last Modified:Apr 22, 2025
    EPS:Mar 9, 2022
    EPSS Score:0.01019
    CVSS Score:3.5

    Affected Products

    Vendor
    Nextcloud
    Product
    Nextcloud Server

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High