Improper Restriction of Excessive Authentication Attempts in Nextcloud Enterprise Server and Nextcloud Server - CVE-2023-45148

 

Improper Restriction of Excessive Authentication Attempts in Nextcloud Enterprise Server and Nextcloud Server - CVE-2023-45148

Published: October 17, 2023


Vulnerability identifier: #VU82071
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-45148
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to improper rate limiter when Memcached is installed. A remote user can cause the rate limiting in Nextcloud Server could be reset unexpectedly resetting the rate count earlier than intended.


Affected software

Nextcloud Enterprise Server
Nextcloud Server

How to mitigate CVE-2023-45148

Install updates from vendor's website.

Nextcloud Enterprise Server - addressed in versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, 27.1.0
Nextcloud Server - addressed in versions 25.0.11, 26.0.6, 27.1.0

External References

Related Security Bulletins