Lucene search

K
cveGitHub_MCVE-2023-25818
HistoryMar 27, 2023 - 8:15 p.m.

CVE-2023-25818

2023-03-2720:15:09
CWE-307
GitHub_M
web.nvd.nist.gov
34
nextcloud
cve-2023-25818
password reset
vulnerability
security update
nextcloud server

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

EPSS

0.001

Percentile

28.0%

Nextcloud server is an open source, personal cloud implementation. In affected versions a malicious user could try to reset the password of another user and then brute force the 62^21 combinations for the password reset token. As of commit 704eb3aa password reset attempts are now throttled. Note that 62^21 combinations would significant compute resources to brute force. None the less it is recommended that the Nextcloud Server is upgraded to 24.0.10 or 25.0.4. There are no known workarounds for this vulnerability.

Affected configurations

Nvd
Vulners
Node
nextcloudnextcloud_serverRange21.0.021.0.9.10enterprise
OR
nextcloudnextcloud_serverRange22.0.022.2.10.10enterprise
OR
nextcloudnextcloud_serverRange23.0.023.0.12.5enterprise
OR
nextcloudnextcloud_serverRange24.0.024.0.10-
OR
nextcloudnextcloud_serverRange24.0.024.0.10enterprise
OR
nextcloudnextcloud_serverRange25.0.025.0.4-
OR
nextcloudnextcloud_serverRange25.0.025.0.4enterprise
VendorProductVersionCPE
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*

CNA Affected

[
  {
    "vendor": "nextcloud",
    "product": "security-advisories",
    "versions": [
      {
        "version": ">= 24.0.0, < 24.0.10",
        "status": "affected"
      },
      {
        "version": ">= 25.0.0, < 25.0.4",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

EPSS

0.001

Percentile

28.0%