CVE-2023-25816: nextcloud vulnerable to Uncontrolled Resource Consumption
Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired. This issue is patched in 25.0.3 No workaround is available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Nextcloud vulnerability?
The vulnerability ID for this Nextcloud vulnerability is CVE-2023-25816.
What is the severity of the CVE-2023-25816 vulnerability?
The severity of the CVE-2023-25816 vulnerability is medium with a CVSS score of 6.5.
Which versions of Nextcloud are affected by CVE-2023-25816?
Versions 25.0.0 and above, prior to 25.0.3, are affected by CVE-2023-25816.
What is the impact of the CVE-2023-25816 vulnerability?
The CVE-2023-25816 vulnerability allows a user to configure a very long password, consuming excessive resources on password validation.
How can the CVE-2023-25816 vulnerability be fixed?
The CVE-2023-25816 vulnerability is fixed in Nextcloud version 25.0.3. It is recommended to update to this version to mitigate the vulnerability.