Brute Force Attack Vulnerability in Nextcloud Server
CVE-2021-22915
9.8CRITICAL
What is CVE-2021-22915?
Nextcloud Server versions prior to 19.0.11, 20.0.10, and 21.0.2 exhibit a vulnerability that makes them susceptible to brute force attacks. This issue arises from the failure to incorporate IPv6 subnets into the existing rate-limiting mechanisms, effectively allowing attackers to bypass protective measures designed to thwart repeated login attempts. Consequently, this oversight endangers the security of user accounts and sensitive data managed by Nextcloud servers.
Affected Version(s)
Nextcloud Server Fixed in 19.0.11, 20.0.10, 21.0.2