Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Primebeast

#52576of 53,624
3.7Total CVSS
Vulnerabilities · 1
PT-2023-19947
3.7
2023-01-16
Nextcloud · Nextcloud Enterprise Server · CVE-2023-25161
**Name of the Vulnerable Software and Affected Versions** Nextcloud Server versions prior to 25.0.1 Nextcloud Server versions prior to 24.0.8 Nextcloud Server versions prior to 23.0.12 Nextcloud Enterprise Server versions prior to 25.0.1 Nextcloud Enterprise Server versions prior to 24.0.8 Nextcloud Enterprise Server versions prior to 23.0.12 **Description** The issue is related to missing rate limiting on password reset functionality in Nextcloud Server and Nextcloud Enterprise Server. This could result in service slowdown, storage overflow, or cost impact when using external email services. **Recommendations** Upgrade to Nextcloud Server 25.0.1 to receive a patch. Upgrade to Nextcloud Server 24.0.8 to receive a patch. Upgrade to Nextcloud Server 23.0.12 to receive a patch. Upgrade to Nextcloud Enterprise Server 25.0.1 to receive a patch. Upgrade to Nextcloud Enterprise Server 24.0.8 to receive a patch. Upgrade to Nextcloud Enterprise Server 23.0.12 to receive a patch.