Lucene search

K
cvelistGitHub_MCVELIST:CVE-2021-41177
HistoryOct 25, 2021 - 9:50 p.m.

CVE-2021-41177 Rate-limits not working on instances without configured memory cache backend

2021-10-2521:50:11
CWE-799
GitHub_M
www.cve.org
5
nextcloud
rate-limiting
vulnerability
memory cache
upgrade

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

8.5

Confidence

High

EPSS

0.004

Percentile

74.2%

Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud Server did not implement a database backend for rate-limiting purposes. Any component of Nextcloud using rate-limits (as as AnonRateThrottle or UserRateThrottle) was thus not rate limited on instances not having a memory cache backend configured. In the case of a default installation, this would notably include the rate-limits on the two factor codes. It is recommended that the Nextcloud Server be upgraded to 20.0.13, 21.0.5, or 22.2.0. As a workaround, enable a memory cache backend in config.php.

CNA Affected

[
  {
    "product": "security-advisories",
    "vendor": "nextcloud",
    "versions": [
      {
        "status": "affected",
        "version": "< 20.0.13"
      },
      {
        "status": "affected",
        "version": ">= 21.0.0, < 21.0.5"
      },
      {
        "status": "affected",
        "version": "< 22.2.0"
      }
    ]
  }
]

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

8.5

Confidence

High

EPSS

0.004

Percentile

74.2%