Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server starting with 25.0.0 and prior to 25.09 and 26.04; as well as Nextcloud Enterprise Server starting with 22.0.0 and prior to 22.2.10.14, 23.0.12.9, 24.0.12.5, 25.0.9, and 26.0.4; missing protection allows an attacker to brute force passwords on the WebDAV API. Nextcloud Server 25.0.9 and 26.0.4 and Nextcloud Enterprise Server 22.2.10.14, 23.0.12.9, 24.0.12.5, 25.0.9, and 26.0.4 contain patches for this issue. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-13T12:07:59.934Z
Updated: 2024-09-17T20:32:00.464Z
Reserved: 2023-08-07T16:27:27.076Z
Link: CVE-2023-39960
Vulnrichment
Updated: 2024-08-02T18:18:10.121Z
NVD
Status : Analyzed
Published: 2023-10-13T13:15:11.560
Modified: 2023-10-18T19:45:38.277
Link: CVE-2023-39960
Redhat
No data.