Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25816


Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired. This issue is patched in 25.0.3 No workaround is available.


Published

2023-02-25T00:15:11.003

Last Modified

2024-11-21T07:50:15.473

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud nextcloud_server < 25.0.3 Yes
Application nextcloud nextcloud_server < 25.0.3 Yes

References