Lucene search

K
cvelistGitHub_MCVELIST:CVE-2023-45148
HistoryOct 16, 2023 - 6:51 p.m.

CVE-2023-45148 Rate limiter not working reliable when Memcached is installed in Nextcloud

2023-10-1618:51:56
CWE-307
GitHub_M
www.cve.org
4
nextcloud
memcached
rate limiter
version upgrade
redis
configuration.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

27.8%

Nextcloud is an open source home cloud server. When Memcached is used as memcache.distributed the rate limiting in Nextcloud Server could be reset unexpectedly resetting the rate count earlier than intended. Users are advised to upgrade to versions 25.0.11, 26.0.6 or 27.1.0. Users unable to upgrade should change their config setting memcache.distributed to \OC\Memcache\Redis and install Redis instead of Memcached.

CNA Affected

[
  {
    "vendor": "nextcloud",
    "product": "security-advisories",
    "versions": [
      {
        "version": ">= 25.0.0, < 25.0.11",
        "status": "affected"
      },
      {
        "version": ">= 26.0.0, < 26.0.6",
        "status": "affected"
      },
      {
        "version": ">= 27.0.0, < 27.1.0",
        "status": "affected"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

27.8%