6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
0.001 Low
EPSS
Percentile
26.2%
An attacker could brute force to find if federated sharing is being used and potentially try to brute force access tokens for federated shares (a-zA-Z0-9
^ 15).
It is recommended that the Nextcloud Server is upgraded to 22.2.9, 23.0.6 or 24.0.2.
As a workaround federated sharing can be disabled in the Admin Sharing settings: index.php/settings/admin/sharing
If you have any questions or comments about this advisory: