CVE-2023-45149
Estado: ModificadaMedia (4.3)—
Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public talk conversation passwords can be bypassed, as there was an endpoint validating the conversation password without registering bruteforce attempts. It is recommended that the Nextcloud Talk app is upgraded to 15.0.8, 16.0.6 or 17.1.1. There are no known workarounds for this vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.48%
- Percentil entre todas las CVEs puntuadas: 39
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-307
Referencias
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7rf8-pqmj-rpqv
- https://github.com/nextcloud/spreed/pull/10545
- https://hackerone.com/reports/2094473
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7rf8-pqmj-rpqv
- https://github.com/nextcloud/spreed/pull/10545
- https://hackerone.com/reports/2094473
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-45149",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-45149",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-16T14:29:14.725109Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "nextcloud",
"product": "security-advisories",
"versions": [
{
"status": "affected",
"version": ">= 15.0.0, < 15.0.8"
},
{
"status": "affected",
"version": ">= 16.0.0, < 16.0.6"
},
{
"status": "affected",
"version": ">= 17.0.0, < 17.1.1"
}
]
}
]
}
],
"published": "2023-10-16T20:15:15.287",
"references": [
{
"url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7rf8-pqmj-rpqv",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nextcloud/spreed/pull/10545",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://hackerone.com/reports/2094473",
"tags": [
"Permissions Required"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7rf8-pqmj-rpqv",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/nextcloud/spreed/pull/10545",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://hackerone.com/reports/2094473",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-307"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public talk conversation passwords can be bypassed, as there was an endpoint validating the conversation password without registering bruteforce attempts. It is recommended that the Nextcloud Talk app is upgraded to 15.0.8, 16.0.6 or 17.1.1. There are no known workarounds for this vulnerability."
},
{
"lang": "es",
"value": "Nextcloud talk es un módulo de chat para la plataforma del servidor Nextcloud. En las versiones afectadas, se puede omitir la protección de fuerza bruta de las contraseñas de conversaciones públicas, ya que había un endpoint que validaba la contraseña de la conversación sin registrar intentos de fuerza bruta. Se recomienda actualizar la aplicación Nextcloud Talk a 15.0.8, 16.0.6 o 17.1.1. No se conocen workarounds para esta vulnerabilidad."
}
],
"lastModified": "2026-06-17T06:28:19.350",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nextcloud:talk:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8F3F3ED-1738-4C2B-9DE7-754D2FC9762E",
"versionEndExcluding": "15.0.8",
"versionStartIncluding": "15.0.0"
},
{
"criteria": "cpe:2.3:a:nextcloud:talk:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BAADB89-AADA-4F5D-B4DB-051FF789E4EA",
"versionEndExcluding": "16.0.6",
"versionStartIncluding": "16.0.0"
},
{
"criteria": "cpe:2.3:a:nextcloud:talk:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2CA92F4-45BF-4290-8926-D4D193461D0A",
"versionEndExcluding": "17.1.1",
"versionStartIncluding": "17.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}