CVE-2023-28847

    Dashboard / Vulnerabilities / CVE-2023-28847

    CVE-2023-28847

    Published: 25 Apr 2023Last Modified: 12 Aug 2026

    Summary: Nextcloud Server missing brute force protection for passwords of password protected share links

    Details: Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24.0.0 prior to 24.0.11 and 25.0.0 prior to 25.0.5; as well as Nextcloud Server Enterprise 23.0.0 prior to 23.0.12.6, 24.0.0 prior to 24.0.11, and 25.0.0 prior to 25.0.5; an attacker is not restricted in verifying passwords of share links so they can just start brute forcing the password. Nextcloud Server 24.0.11 and 25.0.5 and Nextcloud Enterprise Server 23.0.12.6, 24.0.11, and 25.0.5 contain a fix for this issue. No known workarounds are available.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 5f37aacb3194d51503aaa3529ae8f676b32a25d7

    Affected versions

    v24.0.11rc1
    v24.0.10
    v24.0.10rc1
    v24.0.9
    v24.0.9rc2
    v24.0.9rc1
    v24.0.8
    v24.0.8rc2
    v24.0.8rc1
    v24.0.7
    v24.0.7rc1
    v24.0.6
    v24.0.6rc1
    v24.0.5
    v24.0.5rc1
    v24.0.4
    v24.0.4rc1
    v24.0.3
    v24.0.3rc2
    v24.0.3rc1
    v24.0.2
    v24.0.2rc1
    v24.0.1
    v24.0.1rc1
    v24.0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-28847 | CVE-DB