5.3
CVE-2023-25161
- EPSS 0.32%
- Veröffentlicht 13.02.2023 21:15:14
- Zuletzt bearbeitet 21.11.2024 07:49:13
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Nextcloud Server's missing rate limiting on password reset functionality allows sending lots of emails
Missing rate limiting on password reset functionality allows sending lots of emails
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service slowdown, storage overflow, or cost impact when using external email services. Users should upgrade to Nextcloud Server 25.0.1, 24.0.8, or 23.0.12 or Nextcloud Enterprise Server 25.0.1, 24.0.8, or 23.0.12 to receive a patch. No known workarounds are available.
Mögliche Gegenmaßnahme
Server: No workaround available
Server (Enterprise): No workaround available
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextcloud ≫ Nextcloud Server Version < 23.0.12
Nextcloud ≫ Nextcloud Server Version >= 24.0.0 < 24.0.8
Nextcloud ≫ Nextcloud Server Version25.0.0
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemNextcloud
≫
Produkt
Server
Version
>= 0.0.0, < 23.0.12
Version
>= 24.0.0, < 24.0.8
Version
>= 25.0.0, < 25.0.1
SystemNextcloud App
≫
Produkt
Server (Enterprise)
Version
>= 0.0.0, < 23.0.12
Version
>= 24.0.0, < 24.0.8
Version
>= 25.0.0, < 25.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.549 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
| security-advisories@github.com | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.