Rate limiter not working reliable when Memcached is installed
Package
Server
(Nextcloud)
Affected versions
>= 25.0.0, >= 26.0.0, >= 27.0.0
Patched versions
25.0.11, 26.0.6, 27.1.0
Server
(Nextcloud Enterprise)
>= 22.0.0, >= 23.0.0, >= 24.0.0, >= 25.0.0, >= 26.0.0, >= 27.0.0
22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, 27.1.0
Impact
When Memcached is used as
memcache.distributed
the rate limiting in Nextcloud Server could be reset unexpectingly resetting the rate count earlier than intendedPatches
It is recommended that the Nextcloud Server is upgraded to 25.0.11, 26.0.6 or 27.1.0
It is recommended that the Nextcloud Enterprise Server is upgraded to 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6 or 27.1.0
Workarounds
memcache.distributed
to\OC\Memcache\Redis
and install Redis instead of MemcachedReferences
For more information
If you have any questions or comments about this advisory: