5.3

CVE-2023-25161

Nextcloud Server's missing rate limiting on password reset functionality allows sending lots of emails

Missing rate limiting on password reset functionality allows sending lots of emails

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service slowdown, storage overflow, or cost impact when using external email services. Users should upgrade to Nextcloud Server 25.0.1, 24.0.8, or 23.0.12 or Nextcloud Enterprise Server 25.0.1, 24.0.8, or 23.0.12 to receive a patch. No known workarounds are available.
Mögliche Gegenmaßnahme
Server: No workaround available
Server (Enterprise): No workaround available
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudNextcloud Server Version < 23.0.12
NextcloudNextcloud Server Version >= 24.0.0 < 24.0.8
NextcloudNextcloud Server Version25.0.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemNextcloud
Produkt Server
Version >= 0.0.0, < 23.0.12
Version >= 24.0.0, < 24.0.8
Version >= 25.0.0, < 25.0.1
SystemNextcloud App
Produkt Server (Enterprise)
Version >= 0.0.0, < 23.0.12
Version >= 24.0.0, < 24.0.8
Version >= 25.0.0, < 25.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.549
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
security-advisories@github.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.