{"id":"CVE-2022-39364","summary":"Exception logging in Sharepoint app reveals clear-text connection details","details":"Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker reading `nextcloud.log` may gain knowledge of credentials to connect to a SharePoint service. Nextcloud Server versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server versions 22.2.10.5, 23.0.9, and 24.0.5 contain a patch for this issue. As a workaround, set `zend.exception_ignore_args = On` as an option in `php.ini`.","aliases":["GHSA-qpf5-jj85-36h5"],"modified":"2026-07-15T01:49:16.213433737Z","published":"2022-10-27T00:00:00Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-312"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39364.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"22.2.10.5"}]}]},"references":[{"type":"WEB","url":"https://hackerone.com/reports/1652903"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39364.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qpf5-jj85-36h5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39364"},{"type":"REPORT","url":"https://github.com/nextcloud/sharepoint/issues/141"},{"type":"FIX","url":"https://github.com/nextcloud/server/pull/33689"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/server","events":[{"introduced":"0619207f13792250aea775a2c3133d41ab625980"},{"fixed":"19ac8fd167de17fb20d3b718a9bba6943a973fa5"},{"introduced":"5f37aacb3194d51503aaa3529ae8f676b32a25d7"},{"fixed":"e712fab1daf99ad6d1d48f9e851f3a4f90166649"}],"database_specific":{"extracted_events":[{"introduced":"23.0.0"},{"fixed":"23.0.9"},{"introduced":"24.0.0"},{"fixed":"24.0.5"}],"source":"AFFECTED_FIELD"}}],"versions":["v23.0.9rc1","v24.0.5rc1","v23.0.8","v24.0.4","v23.0.8rc1","v24.0.4rc1","v23.0.7","v24.0.3","v23.0.7rc2","v24.0.3rc2","v23.0.7rc1","v24.0.3rc1","v23.0.6","v24.0.2","v23.0.6rc1","v24.0.2rc1","v23.0.5","v24.0.1","v23.0.5rc1","v24.0.1rc1","v24.0.0","v23.0.4","v23.0.4rc1","v23.0.3","v23.0.3rc2","v23.0.3rc1","v23.0.2","v23.0.2rc1","v23.0.1","v23.0.1rc3","v23.0.1rc2","v23.0.1rc1","v23.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39364.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N"}]}