CVE-2023-32319 - CVE House
Back to Database
Status published High CVE-2023-32319

Basic auth header on WebDAV requests is not brute-force protected in Nextcloud

Vulnerability Description

Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints via the basic auth header allowed to brute-force user credentials when the provided user name was not an email address. Users from version 24.0.0 onward are affected. This issue has been addressed in releases 24.0.11, 25.0.5 and 26.0.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-32319

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

security-advisories
Vulnerable Versions:
>= 24.0.0, < 24.0.11, >= 25.0.0, < 25.0.5

Timeline

Official Publish: May 26th, 2023
Last Modified: January 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)