Missing rate limit when trying to join a password protected Nextcloud Talk conversation
Package
Talk
(Nextcloud)
Affected versions
< 12.2.7, < 13.0.7, < 14.0.3
Patched versions
12.2.7, 13.0.7, 14.0.3
Impact
If the conversation is password protected and an attacker got the link/conversation token, they can brute force the password because there is no brute force protection.
Patches
It is recommended that the Nextcloud Talk is upgraded to 12.2.7, 13.0.7 or 14.0.3
Workarounds
No workaround available apart from not having password protected conversations.
References
For more information
If you have any questions or comments about this advisory: