CVE-2023-32319: Basic auth header on WebDAV requests is not brute-force protected in Nextcloud
Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints via the basic auth header allowed to brute-force user credentials when the provided user name was not an email address. Users from version 24.0.0 onward are affected. This issue has been addressed in releases 24.0.11, 25.0.5 and 26.0.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-32319?
CVE-2023-32319 is a vulnerability in the Nextcloud server that allows for brute-force attacks on WebDAV endpoints via the basic auth header.
Which version of Nextcloud is affected by CVE-2023-32319?
Users from version 24.0.0 onward are affected by CVE-2023-32319.
What is the severity of CVE-2023-32319?
CVE-2023-32319 has a severity keyword of 'medium' and a severity value of 6.5.
How can I fix CVE-2023-32319?
To fix CVE-2023-32319, you should update your Nextcloud server to version 24.0.11 or 25.0.5.
Is there any additional information about CVE-2023-32319?
Yes, you can find additional information about CVE-2023-32319 in the Nextcloud security advisories and the GitHub pull request linked in the references.