Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://nextcloud.com/security/advisory/?id=NC-SA-2020-028 | vendor advisory |
https://hackerone.com/reports/840598 | third party advisory exploit |