CVE Vulnerabilities

CVE-2021-41177

Improper Control of Interaction Frequency

Published: Oct 25, 2021 | Modified: Oct 26, 2022
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud Server did not implement a database backend for rate-limiting purposes. Any component of Nextcloud using rate-limits (as as AnonRateThrottle or UserRateThrottle) was thus not rate limited on instances not having a memory cache backend configured. In the case of a default installation, this would notably include the rate-limits on the two factor codes. It is recommended that the Nextcloud Server be upgraded to 20.0.13, 21.0.5, or 22.2.0. As a workaround, enable a memory cache backend in config.php.

Weakness

The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

Affected Software

Name Vendor Start Version End Version
Nextcloud_server Nextcloud * 20.0.13 (excluding)
Nextcloud_server Nextcloud 21.0.0 (including) 21.0.5 (excluding)
Nextcloud_server Nextcloud 22.0.0 (including) 22.2.0 (excluding)

References