First published: Mon Feb 13 2023(Updated: )
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service slowdown, storage overflow, or cost impact when using external email services. Users should upgrade to Nextcloud Server 25.0.1, 24.0.8, or 23.0.12 or Nextcloud Enterprise Server 25.0.1, 24.0.8, or 23.0.12 to receive a patch. No known workarounds are available.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | <23.0.12 | |
Nextcloud Nextcloud Server | >=24.0.0<24.0.8 | |
Nextcloud Nextcloud Server | =25.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Nextcloud Server vulnerability is CVE-2023-25161.
The severity level of CVE-2023-25161 is medium, with a CVSS score of 5.3.
The affected software version range for CVE-2023-25161 is from versions 23.0.12 to 25.0.0 (inclusive).
CVE-2023-25161 can result in service slowdown and storage overflow due to missing rate limiting on password reset functionality.
Yes, you can find references for CVE-2023-25161 at the following links: [1](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-492h-596q-xr2f), [2](https://github.com/nextcloud/server/pull/34632), [3](https://hackerone.com/reports/1691195).