CVE-2023-25161

LOW

Nextcloud Server < 23.0.12, 24.0.8, 25.0.1 - Denial of Service via Password Reset Rate Limit Bypass

Title source: llm
STIX 2.1

Description

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service slowdown, storage overflow, or cost impact when using external email services. Users should upgrade to Nextcloud Server 25.0.1, 24.0.8, or 23.0.12 or Nextcloud Enterprise Server 25.0.1, 24.0.8, or 23.0.12 to receive a patch. No known workarounds are available.

References (3)

Core 3
Core References
Issue Tracking, Patch x_refsource_misc
https://github.com/nextcloud/server/pull/34632
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1691195

Scores

CVSS v3 3.7
EPSS 0.0032
EPSS Percentile 55.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
nextcloud/nextcloud_server 25.0.0
nextcloud/nextcloud_server < 23.0.12
Published Feb 13, 2023
Tracked Since Feb 18, 2026