Improper Restriction of Excessive Authentication Attempts in Nextcloud Enterprise Server and Nextcloud Server - CVE-2023-45148
Published: October 17, 2023
Vulnerability identifier: #VU82071
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-45148
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper rate limiter when Memcached is installed. A remote user can cause the rate limiting in Nextcloud Server could be reset unexpectedly resetting the rate count earlier than intended.
Affected software
Nextcloud Enterprise Server
Nextcloud Server
Nextcloud Server
How to mitigate CVE-2023-45148
Install updates from vendor's website.
Nextcloud Enterprise Server - addressed in versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, 27.1.0
Nextcloud Server - addressed in versions 25.0.11, 26.0.6, 27.1.0
Nextcloud Server - addressed in versions 25.0.11, 26.0.6, 27.1.0