CVE-2023-25161: Nextcloud Server's missing rate limiting on password reset functionality allows sending lots of emails
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service slowdown, storage overflow, or cost impact when using external email services. Users should upgrade to Nextcloud Server 25.0.1, 24.0.8, or 23.0.12 or Nextcloud Enterprise Server 25.0.1, 24.0.8, or 23.0.12 to receive a patch. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Nextcloud Server vulnerability?
The vulnerability ID for this Nextcloud Server vulnerability is CVE-2023-25161.
What is the severity level of CVE-2023-25161?
The severity level of CVE-2023-25161 is medium, with a CVSS score of 5.3.
What is the affected software version range for CVE-2023-25161?
The affected software version range for CVE-2023-25161 is from versions 23.0.12 to 25.0.0 (inclusive).
What is the impact of CVE-2023-25161?
CVE-2023-25161 can result in service slowdown and storage overflow due to missing rate limiting on password reset functionality.
Are there any references available for CVE-2023-25161?
Yes, you can find references for CVE-2023-25161 at the following links: [1](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-492h-596q-xr2f), [2](https://github.com/nextcloud/server/pull/34632), [3](https://hackerone.com/reports/1691195).