openSUSE-SU-2023:0083-1
Dashboard / Vulnerabilities / openSUSE-SU-2023:0083-1
openSUSE-SU-2023:0083-1
Summary: Security update for nextcloud
Details: This update for nextcloud fixes the following issues: - Update to 23.0.12 See: https://nextcloud.com/changelog/#latest23 - This also fix security issues: - CVE-2022-35931: Password Policy app could generate passwords that would be block (boo#1203190) - CVE-2022-39346: Missing length validation of user displayname allows to generate an SQL error (boo#1205802) - CVE-2023-25579: Potential directory traversal in OC\Files\Node\Folder::getFullPath (boo#1208591)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/M7E2FX5KGET4IYNWVYBLR7XYJMJ7SJD4/, https://bugzilla.suse.com/1203190, https://bugzilla.suse.com/1205802, https://bugzilla.suse.com/1208591, https://www.suse.com/security/cve/CVE-2022-35931, https://www.suse.com/security/cve/CVE-2022-39346, https://www.suse.com/security/cve/CVE-2023-25579
Affected packages
Package
Name: nextcloud
Purl: pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
