PT-2023-6442 · Nextcloud+2 · Nextcloud+2

Nickvergessen

·

Published

2023-10-16

·

Updated

2025-01-24

·

CVE-2023-45148

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud versions prior to 25.0.11 Nextcloud versions prior to 26.0.6 Nextcloud versions prior to 27.1.0
Description The issue is related to the use of Memcached as memcache.distributed in Nextcloud, which can cause the rate limiting on the server to be reset unexpectedly, leading to the rate count being reset earlier than intended. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For versions prior to 25.0.11, upgrade to version 25.0.11 or later. For versions prior to 26.0.6, upgrade to version 26.0.6 or later. For versions prior to 27.1.0, upgrade to version 27.1.0 or later. As a temporary workaround for users unable to upgrade, change the config setting memcache.distributed to OCMemcacheRedis and install Redis instead of Memcached.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

ALT-PU-2023-7785
ALT-PU-2023-7786
ALT-PU-2024-1230
ALT-PU-2025-1855
BDU:2023-07158
BDU:2023-07159
CVE-2023-45148
GHSA-XMHP-7VR4-HP63

Affected Products

Alt Linux
Nextcloud
Red Os