Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 848873 (CVE-2022-29243) - <www-apps/nextcloud-{22.2.7,23.0.4}: DoS via very long app passwords
Summary: <www-apps/nextcloud-{22.2.7,23.0.4}: DoS via very long app passwords
Status: IN_PROGRESS
Alias: CVE-2022-29243
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/nextcloud/security...
Whiteboard: B3 [glsa?]
Keywords:
Depends on: 849683
Blocks:
  Show dependency tree
 
Reported: 2022-05-31 23:28 UTC by John Helmert III
Modified: 2022-06-05 20:06 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-05-31 23:28:29 UTC
CVE-2022-29243 (https://github.com/nextcloud/server/pull/31658):
https://hackerone.com/reports/1153138

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.7 and 23.0.4, missing input-size validation of new session names allows users to create app passwords with long names. These long names are then loaded into memory on usage, resulting in impacted performance. Versions 22.2.7 and 23.0.4 contain a fix for this issue. There are currently no known workarounds available.

Please stabilize 23.0.4
Comment 1 Bernard Cafarelli gentoo-dev 2022-06-02 15:57:47 UTC
For 22.2, we only have 22.2.7 so good
For 23, we should indeed stabilize newer version, I would go for 23.0.5 to get more fixes in
Comment 2 Larry the Git Cow gentoo-dev 2022-06-05 19:23:08 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=50f9c464d6b431aafc38e8ad8689b7c648806f3e

commit 50f9c464d6b431aafc38e8ad8689b7c648806f3e
Author:     Bernard Cafarelli <voyageur@gentoo.org>
AuthorDate: 2022-06-05 19:21:20 +0000
Commit:     Bernard Cafarelli <voyageur@gentoo.org>
CommitDate: 2022-06-05 19:23:06 +0000

    www-apps/nextcloud: drop 22.2.7, 23.0.3, 23.0.4
    
    Bug: https://bugs.gentoo.org/848873
    Signed-off-by: Bernard Cafarelli <voyageur@gentoo.org>

 www-apps/nextcloud/Manifest                |  3 ---
 www-apps/nextcloud/nextcloud-22.2.7.ebuild | 43 ------------------------------
 www-apps/nextcloud/nextcloud-23.0.3.ebuild | 43 ------------------------------
 www-apps/nextcloud/nextcloud-23.0.4.ebuild | 43 ------------------------------
 4 files changed, 132 deletions(-)
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-06-05 20:06:52 UTC
Thanks!