5
CVSSv2

CVE-2021-22915

Published: 11/06/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Nextcloud server prior to 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nextcloud nextcloud server

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Nextcloud server before version 2102 did not consider IPv6 subnets in the ratelimiting implementation This could potentially result in an attacker bypassing ratelimit controls such as the Nextcloud bruteforce protection ...