Vulnerability Details CVE-2022-35931
Nextcloud Password Policy is an app that enables a Nextcloud server admin to define certain rules for passwords. Prior to versions 22.2.10, 23.0.7, and 24.0.3 the random password generator may, in very rare cases, generate common passwords that the validator itself would block. Upgrade Nextcloud Server to 22.2.10, 23.0.7 or 24.0.3 to receive a patch for the issue in Password Policy. There are no known workarounds available.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.6%
CVSS Severity
CVSS v3 Score 2.7
Products affected by CVE-2022-35931
-
cpe:2.3:a:nextcloud:password_policy:10.0.1
-
cpe:2.3:a:nextcloud:password_policy:10.0.2
-
cpe:2.3:a:nextcloud:password_policy:10.0.3
-
cpe:2.3:a:nextcloud:password_policy:10.0.4
-
cpe:2.3:a:nextcloud:password_policy:10.0.5
-
cpe:2.3:a:nextcloud:password_policy:10.0.6
-
cpe:2.3:a:nextcloud:password_policy:11.0.0
-
cpe:2.3:a:nextcloud:password_policy:11.0.1
-
cpe:2.3:a:nextcloud:password_policy:11.0.2
-
cpe:2.3:a:nextcloud:password_policy:11.0.3
-
cpe:2.3:a:nextcloud:password_policy:11.0.4
-
cpe:2.3:a:nextcloud:password_policy:11.0.5
-
cpe:2.3:a:nextcloud:password_policy:11.0.6
-
cpe:2.3:a:nextcloud:password_policy:11.0.7
-
cpe:2.3:a:nextcloud:password_policy:11.0.8
-
cpe:2.3:a:nextcloud:password_policy:12.0.0
-
cpe:2.3:a:nextcloud:password_policy:12.0.1
-
cpe:2.3:a:nextcloud:password_policy:12.0.10
-
cpe:2.3:a:nextcloud:password_policy:12.0.11
-
cpe:2.3:a:nextcloud:password_policy:12.0.12
-
cpe:2.3:a:nextcloud:password_policy:12.0.13
-
cpe:2.3:a:nextcloud:password_policy:12.0.2
-
cpe:2.3:a:nextcloud:password_policy:12.0.3
-
cpe:2.3:a:nextcloud:password_policy:12.0.4
-
cpe:2.3:a:nextcloud:password_policy:12.0.5
-
cpe:2.3:a:nextcloud:password_policy:12.0.6
-
cpe:2.3:a:nextcloud:password_policy:12.0.7
-
cpe:2.3:a:nextcloud:password_policy:12.0.8
-
cpe:2.3:a:nextcloud:password_policy:12.0.9
-
cpe:2.3:a:nextcloud:password_policy:13.0.0
-
cpe:2.3:a:nextcloud:password_policy:13.0.1
-
cpe:2.3:a:nextcloud:password_policy:13.0.10
-
cpe:2.3:a:nextcloud:password_policy:13.0.11
-
cpe:2.3:a:nextcloud:password_policy:13.0.12
-
cpe:2.3:a:nextcloud:password_policy:13.0.2
-
cpe:2.3:a:nextcloud:password_policy:13.0.3
-
cpe:2.3:a:nextcloud:password_policy:13.0.4
-
cpe:2.3:a:nextcloud:password_policy:13.0.5
-
cpe:2.3:a:nextcloud:password_policy:13.0.6
-
cpe:2.3:a:nextcloud:password_policy:13.0.7
-
cpe:2.3:a:nextcloud:password_policy:13.0.8
-
cpe:2.3:a:nextcloud:password_policy:13.0.9
-
cpe:2.3:a:nextcloud:password_policy:14.0.0
-
cpe:2.3:a:nextcloud:password_policy:14.0.1
-
cpe:2.3:a:nextcloud:password_policy:14.0.10
-
cpe:2.3:a:nextcloud:password_policy:14.0.11
-
cpe:2.3:a:nextcloud:password_policy:14.0.12
-
cpe:2.3:a:nextcloud:password_policy:14.0.13
-
cpe:2.3:a:nextcloud:password_policy:14.0.14
-
cpe:2.3:a:nextcloud:password_policy:14.0.2
-
cpe:2.3:a:nextcloud:password_policy:14.0.3
-
cpe:2.3:a:nextcloud:password_policy:14.0.4
-
cpe:2.3:a:nextcloud:password_policy:14.0.5
-
cpe:2.3:a:nextcloud:password_policy:14.0.6
-
cpe:2.3:a:nextcloud:password_policy:14.0.7
-
cpe:2.3:a:nextcloud:password_policy:14.0.8
-
cpe:2.3:a:nextcloud:password_policy:14.0.9
-
cpe:2.3:a:nextcloud:password_policy:15.0.0
-
cpe:2.3:a:nextcloud:password_policy:15.0.1
-
cpe:2.3:a:nextcloud:password_policy:15.0.10
-
cpe:2.3:a:nextcloud:password_policy:15.0.11
-
cpe:2.3:a:nextcloud:password_policy:15.0.12
-
cpe:2.3:a:nextcloud:password_policy:15.0.13
-
cpe:2.3:a:nextcloud:password_policy:15.0.14
-
cpe:2.3:a:nextcloud:password_policy:15.0.2
-
cpe:2.3:a:nextcloud:password_policy:15.0.3
-
cpe:2.3:a:nextcloud:password_policy:15.0.4
-
cpe:2.3:a:nextcloud:password_policy:15.0.5
-
cpe:2.3:a:nextcloud:password_policy:15.0.6
-
cpe:2.3:a:nextcloud:password_policy:15.0.7
-
cpe:2.3:a:nextcloud:password_policy:15.0.8
-
cpe:2.3:a:nextcloud:password_policy:15.0.9
-
cpe:2.3:a:nextcloud:password_policy:16.0.0
-
cpe:2.3:a:nextcloud:password_policy:16.0.1
-
cpe:2.3:a:nextcloud:password_policy:16.0.10
-
cpe:2.3:a:nextcloud:password_policy:16.0.11
-
cpe:2.3:a:nextcloud:password_policy:16.0.2
-
cpe:2.3:a:nextcloud:password_policy:16.0.3
-
cpe:2.3:a:nextcloud:password_policy:16.0.4
-
cpe:2.3:a:nextcloud:password_policy:16.0.5
-
cpe:2.3:a:nextcloud:password_policy:16.0.6
-
cpe:2.3:a:nextcloud:password_policy:16.0.7
-
cpe:2.3:a:nextcloud:password_policy:16.0.8
-
cpe:2.3:a:nextcloud:password_policy:16.0.9
-
cpe:2.3:a:nextcloud:password_policy:17.0.0
-
cpe:2.3:a:nextcloud:password_policy:17.0.1
-
cpe:2.3:a:nextcloud:password_policy:17.0.10
-
cpe:2.3:a:nextcloud:password_policy:17.0.2
-
cpe:2.3:a:nextcloud:password_policy:17.0.3
-
cpe:2.3:a:nextcloud:password_policy:17.0.4
-
cpe:2.3:a:nextcloud:password_policy:17.0.5
-
cpe:2.3:a:nextcloud:password_policy:17.0.6
-
cpe:2.3:a:nextcloud:password_policy:17.0.7
-
cpe:2.3:a:nextcloud:password_policy:17.0.8
-
cpe:2.3:a:nextcloud:password_policy:17.0.9
-
cpe:2.3:a:nextcloud:password_policy:18.0.0
-
cpe:2.3:a:nextcloud:password_policy:18.0.1
-
cpe:2.3:a:nextcloud:password_policy:18.0.10
-
cpe:2.3:a:nextcloud:password_policy:18.0.11
-
cpe:2.3:a:nextcloud:password_policy:18.0.12
-
cpe:2.3:a:nextcloud:password_policy:18.0.13
-
cpe:2.3:a:nextcloud:password_policy:18.0.14
-
cpe:2.3:a:nextcloud:password_policy:18.0.2
-
cpe:2.3:a:nextcloud:password_policy:18.0.4
-
cpe:2.3:a:nextcloud:password_policy:18.0.5
-
cpe:2.3:a:nextcloud:password_policy:18.0.6
-
cpe:2.3:a:nextcloud:password_policy:18.0.7
-
cpe:2.3:a:nextcloud:password_policy:18.0.8
-
cpe:2.3:a:nextcloud:password_policy:18.0.9
-
cpe:2.3:a:nextcloud:password_policy:19.0.0
-
cpe:2.3:a:nextcloud:password_policy:19.0.1
-
cpe:2.3:a:nextcloud:password_policy:19.0.10
-
cpe:2.3:a:nextcloud:password_policy:19.0.11
-
cpe:2.3:a:nextcloud:password_policy:19.0.12
-
cpe:2.3:a:nextcloud:password_policy:19.0.13
-
cpe:2.3:a:nextcloud:password_policy:19.0.2
-
cpe:2.3:a:nextcloud:password_policy:19.0.3
-
cpe:2.3:a:nextcloud:password_policy:19.0.4
-
cpe:2.3:a:nextcloud:password_policy:19.0.5
-
cpe:2.3:a:nextcloud:password_policy:19.0.6
-
cpe:2.3:a:nextcloud:password_policy:19.0.7
-
cpe:2.3:a:nextcloud:password_policy:19.0.8
-
cpe:2.3:a:nextcloud:password_policy:19.0.9
-
cpe:2.3:a:nextcloud:password_policy:20.0.0
-
cpe:2.3:a:nextcloud:password_policy:20.0.1
-
cpe:2.3:a:nextcloud:password_policy:20.0.10
-
cpe:2.3:a:nextcloud:password_policy:20.0.11
-
cpe:2.3:a:nextcloud:password_policy:20.0.12
-
cpe:2.3:a:nextcloud:password_policy:20.0.13
-
cpe:2.3:a:nextcloud:password_policy:20.0.14
-
cpe:2.3:a:nextcloud:password_policy:20.0.2
-
cpe:2.3:a:nextcloud:password_policy:20.0.3
-
cpe:2.3:a:nextcloud:password_policy:20.0.4
-
cpe:2.3:a:nextcloud:password_policy:20.0.5
-
cpe:2.3:a:nextcloud:password_policy:20.0.6
-
cpe:2.3:a:nextcloud:password_policy:20.0.7
-
cpe:2.3:a:nextcloud:password_policy:20.0.8
-
cpe:2.3:a:nextcloud:password_policy:20.0.9
-
cpe:2.3:a:nextcloud:password_policy:21.0.0
-
cpe:2.3:a:nextcloud:password_policy:21.0.1
-
cpe:2.3:a:nextcloud:password_policy:21.0.2
-
cpe:2.3:a:nextcloud:password_policy:21.0.3
-
cpe:2.3:a:nextcloud:password_policy:21.0.4
-
cpe:2.3:a:nextcloud:password_policy:21.0.5
-
cpe:2.3:a:nextcloud:password_policy:21.0.6
-
cpe:2.3:a:nextcloud:password_policy:21.0.7
-
cpe:2.3:a:nextcloud:password_policy:21.0.8
-
cpe:2.3:a:nextcloud:password_policy:21.0.9
-
cpe:2.3:a:nextcloud:password_policy:22.0.0
-
cpe:2.3:a:nextcloud:password_policy:22.1.0
-
cpe:2.3:a:nextcloud:password_policy:22.1.1
-
cpe:2.3:a:nextcloud:password_policy:22.2.0
-
cpe:2.3:a:nextcloud:password_policy:22.2.1
-
cpe:2.3:a:nextcloud:password_policy:22.2.2
-
cpe:2.3:a:nextcloud:password_policy:22.2.3
-
cpe:2.3:a:nextcloud:password_policy:22.2.4
-
cpe:2.3:a:nextcloud:password_policy:22.2.5
-
cpe:2.3:a:nextcloud:password_policy:22.2.6
-
cpe:2.3:a:nextcloud:password_policy:22.2.7
-
cpe:2.3:a:nextcloud:password_policy:22.2.8
-
cpe:2.3:a:nextcloud:password_policy:22.2.9
-
cpe:2.3:a:nextcloud:password_policy:23.0.0
-
cpe:2.3:a:nextcloud:password_policy:23.0.1
-
cpe:2.3:a:nextcloud:password_policy:23.0.2
-
cpe:2.3:a:nextcloud:password_policy:23.0.3
-
cpe:2.3:a:nextcloud:password_policy:23.0.4
-
cpe:2.3:a:nextcloud:password_policy:23.0.5
-
cpe:2.3:a:nextcloud:password_policy:23.0.6
-
cpe:2.3:a:nextcloud:password_policy:24.0.0
-
cpe:2.3:a:nextcloud:password_policy:24.0.1
-
cpe:2.3:a:nextcloud:password_policy:24.0.2
-
cpe:2.3:a:nextcloud:password_policy:9.0.52
-
cpe:2.3:a:nextcloud:password_policy:9.0.54
-
cpe:2.3:a:nextcloud:password_policy:9.0.55
-
cpe:2.3:a:nextcloud:password_policy:9.0.56
-
cpe:2.3:a:nextcloud:password_policy:9.0.57
-
cpe:2.3:a:nextcloud:password_policy:9.0.58