CVE-2021-22915: Critical severity Nextcloud Server vulnerability
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22915?
CVE-2021-22915 is considered a moderate severity vulnerability due to its potential for allowing brute-force attacks.
How do I fix CVE-2021-22915?
To fix CVE-2021-22915, upgrade to Nextcloud server version 19.0.11, 20.0.10, or 21.0.2 or later.
What types of attacks are associated with CVE-2021-22915?
CVE-2021-22915 is associated with brute force attacks that exploit the lack of IPv6 subnet rate-limiting.
Which versions of Nextcloud are affected by CVE-2021-22915?
CVE-2021-22915 affects Nextcloud server versions prior to 19.0.11, 20.0.10, and 21.0.2.
Is CVE-2021-22915 specific to IPv6 users?
Yes, CVE-2021-22915 specifically impacts users leveraging IPv6 due to inadequate rate limiting in Nextcloud.