CVE-2021-22915Improper Restriction of Excessive Authentication Attempts in Server

Severity
9.8CRITICALNVD
EPSS
0.5%
top 34.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11

Description

Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDnextcloud/nextcloud_server20.0.020.0.10+2
CVEListV5nextcloud/nextcloud_serverFixed in 19.0.11, 20.0.10, 21.0.2

Also affects: Fedora 33, 34

🔴Vulnerability Details

1
CVEList
CVE-2021-22915: Nextcloud server before 192021-06-11
CVE-2021-22915 — Nextcloud Server vulnerability | cvebase