Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 848873 (CVE-2022-29243) - <www-apps/nextcloud-{22.2.7,23.0.4}: DoS via very long app passwords
Summary: <www-apps/nextcloud-{22.2.7,23.0.4}: DoS via very long app passwords
Status: RESOLVED FIXED
Alias: CVE-2022-29243
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/nextcloud/security...
Whiteboard: B3 [glsa+]
Keywords:
Depends on: 849683
Blocks:
  Show dependency tree
 
Reported: 2022-05-31 23:28 UTC by John Helmert III
Modified: 2022-08-10 22:36 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-05-31 23:28:29 UTC
CVE-2022-29243 (https://github.com/nextcloud/server/pull/31658):
https://hackerone.com/reports/1153138

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.7 and 23.0.4, missing input-size validation of new session names allows users to create app passwords with long names. These long names are then loaded into memory on usage, resulting in impacted performance. Versions 22.2.7 and 23.0.4 contain a fix for this issue. There are currently no known workarounds available.

Please stabilize 23.0.4
Comment 1 Bernard Cafarelli gentoo-dev 2022-06-02 15:57:47 UTC
For 22.2, we only have 22.2.7 so good
For 23, we should indeed stabilize newer version, I would go for 23.0.5 to get more fixes in
Comment 2 Larry the Git Cow gentoo-dev 2022-06-05 19:23:08 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=50f9c464d6b431aafc38e8ad8689b7c648806f3e

commit 50f9c464d6b431aafc38e8ad8689b7c648806f3e
Author:     Bernard Cafarelli <voyageur@gentoo.org>
AuthorDate: 2022-06-05 19:21:20 +0000
Commit:     Bernard Cafarelli <voyageur@gentoo.org>
CommitDate: 2022-06-05 19:23:06 +0000

    www-apps/nextcloud: drop 22.2.7, 23.0.3, 23.0.4
    
    Bug: https://bugs.gentoo.org/848873
    Signed-off-by: Bernard Cafarelli <voyageur@gentoo.org>

 www-apps/nextcloud/Manifest                |  3 ---
 www-apps/nextcloud/nextcloud-22.2.7.ebuild | 43 ------------------------------
 www-apps/nextcloud/nextcloud-23.0.3.ebuild | 43 ------------------------------
 www-apps/nextcloud/nextcloud-23.0.4.ebuild | 43 ------------------------------
 4 files changed, 132 deletions(-)
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-06-05 20:06:52 UTC
Thanks!
Comment 4 Larry the Git Cow gentoo-dev 2022-08-10 22:33:40 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=b56f993e2e4fa0778f67ba7d3b8fbb350d4c7386

commit b56f993e2e4fa0778f67ba7d3b8fbb350d4c7386
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2022-08-10 22:31:11 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2022-08-10 22:33:19 +0000

    [ GLSA 202208-17 ] Nextcloud: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/797253
    Bug: https://bugs.gentoo.org/802096
    Bug: https://bugs.gentoo.org/812443
    Bug: https://bugs.gentoo.org/820368
    Bug: https://bugs.gentoo.org/834803
    Bug: https://bugs.gentoo.org/835073
    Bug: https://bugs.gentoo.org/848873
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 glsa-202208-17.xml | 72 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 72 insertions(+)
Comment 5 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-10 22:36:57 UTC
GLSA released, all done!