No password length restriction in reset password endpoint
Package
Server
(Nextcloud)
Affected versions
>= 25.0.0
Patched versions
25.0.3
Server
(Nextcloud Enterprise)
>= 25.0.0
25.0.3
Impact
A user can configure a very long password consuming more resources on password validation then desired.
Patches
It is recommended that the Nextcloud Server is upgraded to 25.0.3
It is recommended that the Nextcloud Enterprise Server is upgraded to 25.0.3
Workarounds
References
For more information
If you have any questions or comments about this advisory: