Vulnerability CVE-2023-45148: Information

Description

Nextcloud is an open source home cloud server. When Memcached is used as `memcache.distributed` the rate limiting in Nextcloud Server could be reset unexpectedly resetting the rate count earlier than intended. Users are advised to upgrade to versions 25.0.11, 26.0.6 or 27.1.0. Users unable to upgrade should change their config setting `memcache.distributed` to `\OC\Memcache\Redis` and install Redis instead of Memcached.

Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Published: Oct. 16, 2023
Modified: Oct. 20, 2023
Error type identifier: CWE-307

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
nextcloudsisyphus27.1.4-alt129.0.0-alt1ALT-PU-2023-7786-2331928Fixed
nextcloudsisyphus_e2k27.1.4-alt129.0.0-alt1ALT-PU-2023-8114-1-Fixed
nextcloudsisyphus_loongarch6427.1.4-alt129.0.0-alt1ALT-PU-2023-8099-1-Fixed
nextcloudp1026.0.9-alt0.p10.127.1.4-alt1ALT-PU-2023-7785-2335752Fixed
nextcloudp10_e2k26.0.9-alt0.p10.127.1.4-alt1ALT-PU-2023-7955-1-Fixed
nextcloudp1127.1.4-alt129.0.0-alt1ALT-PU-2023-7786-2331928Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:nextcloud:nextcloud_server:27.0.0:*:*:*:-:*:*:*

      cpe:2.3:a:nextcloud:nextcloud_server:27.0.0:*:*:*:enterprise:*:*:*

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      22.0.0
      End excliding
      22.2.10.16

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      23.0.0
      End excliding
      23.0.12.11

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      24.0.0
      End excliding
      24.0.12.7

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      26.0.0
      End excliding
      26.0.6

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
      Start including
      26.0.0
      End excliding
      26.0.6

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
      Start including
      25.0.0
      End excliding
      25.0.11

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      25.0.0
      End excliding
      25.0.11