Bug 1203190 (CVE-2022-35931) - VUL-1: CVE-2022-35931: nextcloud: Password Policy app could generate passwords that would be block
Summary: VUL-1: CVE-2022-35931: nextcloud: Password Policy app could generate password...
Status: RESOLVED FIXED
Alias: CVE-2022-35931
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.5
Hardware: Other Other
: P4 - Low : Normal (vote)
Target Milestone: ---
Assignee: Eric Schirra
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/341558/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-09-07 06:30 UTC by Robert Frohl
Modified: 2024-04-16 08:16 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2022-09-07 06:30:51 UTC
CVE-2022-35931

Nextcloud Password Policy is an app that enables a Nextcloud server admin to
define certain rules for passwords. Prior to versions 22.2.10, 23.0.7, and
24.0.3 the random password generator may, in very rare cases, generate common
passwords that the validator itself would block. Upgrade Nextcloud Server to
22.2.10, 23.0.7 or 24.0.3 to receive a patch for the issue in Password Policy.
There are no known workarounds available.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-35931
https://www.cve.org/CVERecord?id=CVE-2022-35931
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-c7mw-9q4r-8qwr
https://github.com/nextcloud/password_policy/pull/363
Comment 1 Robert Frohl 2022-09-07 06:33:43 UTC
already fixed in Factory and openSUSE:Backports:SLE-15-SP5/nextcloud, still relevant for older Backports versions (for example openSUSE:Backports:SLE-15-SP4/nextcloud)
Comment 2 OBSbugzilla Bot 2023-04-01 10:55:02 UTC
This is an autogenerated message for OBS integration:
This bug (1203190) was mentioned in
https://build.opensuse.org/request/show/1076615 Backports:SLE-15-SP4 / nextcloud
Comment 3 Swamp Workflow Management 2023-04-03 19:05:30 UTC
openSUSE-SU-2023:0083-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1203190,1205802,1208591
CVE References: CVE-2022-35931,CVE-2022-39346,CVE-2023-25579
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP4 (src):    nextcloud-23.0.12-bp154.2.3.1
Comment 4 Eric Schirra 2024-04-16 08:16:22 UTC
is accepted