Lucene search

K
cveGitHub_MCVE-2023-45148
HistoryOct 16, 2023 - 7:15 p.m.

CVE-2023-45148

2023-10-1619:15:10
CWE-307
GitHub_M
web.nvd.nist.gov
43
nextcloud
server
memcached
rate limiting
upgrades
security advisory

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

27.8%

Nextcloud is an open source home cloud server. When Memcached is used as memcache.distributed the rate limiting in Nextcloud Server could be reset unexpectedly resetting the rate count earlier than intended. Users are advised to upgrade to versions 25.0.11, 26.0.6 or 27.1.0. Users unable to upgrade should change their config setting memcache.distributed to \OC\Memcache\Redis and install Redis instead of Memcached.

Affected configurations

Nvd
Vulners
Node
nextcloudnextcloud_serverRange22.0.022.2.10.16enterprise
OR
nextcloudnextcloud_serverRange23.0.023.0.12.11enterprise
OR
nextcloudnextcloud_serverRange24.0.024.0.12.7enterprise
OR
nextcloudnextcloud_serverRange25.0.025.0.11-
OR
nextcloudnextcloud_serverRange25.0.025.0.11enterprise
OR
nextcloudnextcloud_serverRange26.0.026.0.6-
OR
nextcloudnextcloud_serverRange26.0.026.0.6enterprise
OR
nextcloudnextcloud_serverMatch27.0.0-
OR
nextcloudnextcloud_serverMatch27.0.0enterprise
VendorProductVersionCPE
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
nextcloudnextcloud_server27.0.0cpe:2.3:a:nextcloud:nextcloud_server:27.0.0:*:*:*:-:*:*:*
nextcloudnextcloud_server27.0.0cpe:2.3:a:nextcloud:nextcloud_server:27.0.0:*:*:*:enterprise:*:*:*

CNA Affected

[
  {
    "vendor": "nextcloud",
    "product": "security-advisories",
    "versions": [
      {
        "version": ">= 25.0.0, < 25.0.11",
        "status": "affected"
      },
      {
        "version": ">= 26.0.0, < 26.0.6",
        "status": "affected"
      },
      {
        "version": ">= 27.0.0, < 27.1.0",
        "status": "affected"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

27.8%