CVE-2023-25816

CVSS V2 None CVSS V3 None
Description
Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired. This issue is patched in 25.0.3 No workaround is available.
Overview
  • CVE ID
  • CVE-2023-25816
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-25T00:15:11
  • Last Modified Date
  • 2023-03-07T16:38:23
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 1 OR 25.0.0 25.0.3
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* 1 OR 25.0.0 25.0.3
History
Created Old Value New Value Data Type Notes
2023-04-17 05:26:30 Added to TrackCVE
2023-04-17 05:26:33 Weakness Enumeration new