CVE-2022-3423

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to consume excessive system resources on the nocodb application, potentially leading to service slowdowns or crashes. It can be exploited if the attacker has access to the application and can send requests that overwhelm the system.

Technical Description

Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactNone
Integrity ImpactNone
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$931($500-$1K)
Vendor Response
Grade FPatched in 1237 days

Quick Information

Published

Oct 7, 2022

over 3 years ago

Last Modified

Feb 25, 2026

about 1 month ago

Vendor

nocodb

Product

nocodb