CVE-2023-25816 Information

Description

Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above prior to 25.0.3 are subject to Uncontrolled Resource Consumption. A user can configure a very long password consuming more resources on password validation than desired. This issue is patched in 25.0.3 No workaround is available.

Reference

https://hackerone.com/reports/1820864 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-53q2-cm29-7j83 https://github.com/nextcloud/server/pull/35965

Share on: