Critical severity9.8NVD Advisory· Published Jun 11, 2021· Updated Jun 17, 2026
CVE-2021-22915
CVE-2021-22915
Description
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- Range: <19.0.11, <20.0.10, <21.0.2
Patches
Vulnerability mechanics
References
4- hackerone.com/reports/1154003nvdPermissions RequiredThird Party Advisory
- nextcloud.com/security/advisory/nvdBroken Link
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AGXGR6HYGQ6MZXISMJEHCOXRGRFRUFMA/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L6BO6P6MP2MOWA6PZRXX32PLWPXN5O4S/nvd
News mentions
0No linked articles in our index yet.