Nextcloud Server has improper restriction of excessive authentication attempts on WebDAV endpoint
CVE-2023-39960
What is CVE-2023-39960?
Nextcloud Server, a widely used open-source cloud platform, is susceptible to brute force attacks via its WebDAV API. The vulnerability exists in versions starting from 25.0.0 up to 25.09 and 26.04, as well as in Nextcloud Enterprise Server versions from 22.0.0 up to 22.2.10.14, 23.0.12.9, 24.0.12.5, 25.0.9, and 26.0.4, allowing attackers to attempt password brute-force techniques without sufficient protections in place. This opens a potential avenue for unauthorized access to users' sensitive information. Users are urged to upgrade their installations to the patched versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
security-advisories >= 22.0.0, < 22.2.10.14 < 22.0.0, 22.2.10.14
security-advisories >= 23.0.0, < 23.0.12.9 < 23.0.0, 23.0.12.9
security-advisories >= 24.0.0, < 24.0.12.5 < 24.0.0, 24.0.12.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved