GLSA 202208-17: Nextcloud: Multiple Vulnerabilities
Severity: | low |
Title: | Nextcloud: Multiple Vulnerabilities |
Date: | 08/10/2022 |
Bugs: |
|
ID: | 202208-17 |
Synopsis
Multiple vulnerabilities have been found in Nextcloud, the worst of which could result in denial of service.Background
Nextcloud is a personal cloud that runs on your own server.
Affected packages
Package | Vulnerable | Unaffected | Architecture(s) |
---|---|---|---|
www-apps/nextcloud | < 23.0.4 | >= 23.0.4 | All supported architectures |
Description
Multiple vulnerabilities have been discovered in Nextcloud. Please review the CVE identifiers referenced below for details.
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.
Resolution
All Nextcloud users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=www-apps/nextcloud-23.0.4"
References
CVE-2022-29243 CVE-2022-24889 CVE-2022-24888 CVE-2022-24741 CVE-2021-41241 CVE-2021-41239 CVE-2021-41178 CVE-2021-41177 CVE-2021-32802 CVE-2021-32801 CVE-2021-32800 CVE-2021-32734 CVE-2021-32726 CVE-2021-32725 CVE-2021-32705 CVE-2021-32703 CVE-2021-32688 CVE-2021-32680 CVE-2021-32679 CVE-2021-32678 CVE-2021-32657 CVE-2021-32656 CVE-2021-32655 CVE-2021-32654 CVE-2021-32653
Availability
This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.
License
Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.