CVE-2021-22915 log

Source
Severity Low
Remote Yes
Type Access restriction bypass
Description
Nextcloud server before version 21.0.2 did not consider IPv6 subnets in the ratelimiting implementation. This could potentially result in an attacker bypassing ratelimit controls such as the Nextcloud bruteforce protection.
Group Package Affected Fixed Severity Status Ticket
AVG-2024 nextcloud 21.0.1-3 21.0.2-1 High Fixed
References
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2967-6mrp-gg3p
https://hackerone.com/reports/1154003