CVE-2023-35172
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0 until 24.0.12.2, 25.0.0 until 25.0.7, and 26.0.0 until 26.0.2, an attacker can bruteforce the password reset links. Nextcloud Server n 25.0.7 and 26.0.2 and Nextcloud Enterprise Server 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, and 26.0.2 contain a patch for this issue. No known workarounds are available.
- Affected products
- Alt Linux, Nextcloud Enterprise Server, Nextcloud Server, Red Os
- Nextcloud Nextcloud Server
- < 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, 26.0.2
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.9% (57th percentile)
- Weakness
- CWE-307
- NVD status
- Modified
- Published
- 2023-06-23
No indexed exploits for CVE-2023-35172 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-35172 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.