No set limit to try to login in "https://auth.nextcloud.com/auth/realms/master/protocol/openid-connect/auth" page.

Disclosed: 2021-04-20 13:50:20 By syachineko To nextcloud
Unknown
Vulnerability Details
Hi. I checked the "https://nextcloud.com" page, and try to go to wp-admin page. Then, I found the login page "https://auth.nextcloud.com/auth/realms/master/protocol/openid-connect/auth" In this page, I tried to login more than 10 times!(manually) I think that I can try to brute force to this login page, because it's no limit to try to login. You should be better to set the limit to try to login. ## Impact an attacker can try to brute force attack to login the page until he can success to login.
Actions
View on HackerOne
Report Stats
  • Report ID: 855304
  • State: Closed
  • Substate: informative
  • Upvotes: 3
Share this report