CVE-2023-45149: Nextcloud Talk
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public talk conversation passwords can be bypassed, as there was an endpoint validating the conversation password without registering bruteforce attempts. It is recommended that the Nextcloud Talk app is upgraded to 15.0.8, 16.0.6 or 17.1.1. There are no known workarounds for this vulnerability.
Affected products
- Nextcloud Talk: from 15.0.0, before 15.0.8 (fixed in 15.0.8); from 16.0.0, before 16.0.6 (fixed in 16.0.6); from 17.0.0, before 17.1.1 (fixed in 17.1.1)
Published 2023-10-16. Last modified 2026-06-17.