← Back

CVE-2021-22915

nvd nist
Published: Jun 11, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.

Affected (5)

1 product
Nextcloud Server
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
Before 19.0.11
From 20.0.0 to 20.0.10
From 21.0.0 to 21.0.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34

Timeline

No history available yet.