CVE-2022-31119
Last modified
CVE-2022-31119 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail would log user passwords to disk in the event of a misconfiguration. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail would log user passwords to disk in the event of a misconfiguration. Should an attacker gain access to the logs complete access to affected accounts would be obtainable. It is recommended that the Nextcloud Mail is upgraded to 1.12.1. Operators should inspect their logs and remove passwords which have been logged. There are no workarounds to prevent logging in the event of a misconfiguration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | < 1.12.1 |
References
- https://github.com/nextcloud/mail/issues/823Third Party Advisory
- https://github.com/nextcloud/mail/pull/6488/commits/ab9ade57fbc1f465ffe905248f93f328d638d7e5Patch, Third Party Advisory
- https://github.com/nextcloud/mail/issues/823Third Party Advisory
- https://github.com/nextcloud/mail/pull/6488/commits/ab9ade57fbc1f465ffe905248f93f328d638d7e5Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-31119?
How severe is CVE-2022-31119?
How do I fix CVE-2022-31119?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31113Canarytokens is an open source tool which helps track activi…6.1
- CVE-2022-31114backpack/crud provides Create, Read, Update & Delete (CRUD) …5.1
- CVE-2022-31115opensearch-ruby is a community-driven, open source fork of e…8.8
- CVE-2022-31116UltraJSON is a fast JSON encoder and decoder written in pure…7.5
- CVE-2022-31117UltraJSON is a fast JSON encoder and decoder written in pure…5.9
- CVE-2022-31118Nextcloud server is an open source personal cloud solution. …5.3
- CVE-2022-3112An issue was discovered in the Linux kernel through 5.16-rc6…5.5
- CVE-2022-31120Nextcloud server is an open source personal cloud solution. …2.7
- CVE-2022-31121Hyperledger Fabric is a permissioned distributed ledger fram…7.5
- CVE-2022-31122Wire is an encrypted communication and collaboration platfor…8.1
- CVE-2022-31123Grafana is an open source observability and data visualizati…7.8
- CVE-2022-31124openssh_key_parser is an open source Python package providin…6.5
Are you affected by CVE-2022-31119?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
