← Back

CVE-2023-35172

nvd nist
Published: Jun 23, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0 until 24.0.12.2, 25.0.0 until 25.0.7, and 26.0.0 until 26.0.2, an attacker can bruteforce the password reset links. Nextcloud Server n 25.0.7 and 26.0.2 and Nextcloud Enterprise Server 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, and 26.0.2 contain a patch for this issue. No known workarounds are available.

Affected (8)

1 product
Nextcloud Server
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
From 25.0.0 to 25.0.7
From 26.0.0 to 26.0.2
From 21.0.0 to 21.0.9.12
From 22.0.0 to 22.2.10.12
From 23.0.0 to 23.0.12.7
From 24.0.0 to 24.0.12.2
From 25.0.0 to 25.0.7
From 26.0.0 to 26.0.2

References (6)

Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.