CVE-2023-22470
Dashboard / Vulnerabilities / CVE-2023-22470
Summary: Nextcloud Deck vulnerable to uncontrolled resource consumption
Details: Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently no known workarounds. It is recommended that the Nextcloud Server is upgraded to 1.6.5 or 1.7.3 or 1.8.2.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/22xxx/CVE-2023-22470.json, https://github.com/nextcloud/security-advisories/security/advisories/GHSA-93j5-wx4c-6g88, https://nvd.nist.gov/vuln/detail/CVE-2023-22470, https://github.com/nextcloud/deck/pull/4059
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
