Vulnerability Description
user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | User Oidc | < 1.3.2 |
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x8mc-8Vendor Advisory
- https://github.com/nextcloud/user_oidc/pull/615Issue TrackingPatch
- https://hackerone.com/reports/1954711Permissions Required
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x8mc-8Vendor Advisory
- https://github.com/nextcloud/user_oidc/pull/615Issue TrackingPatch
- https://hackerone.com/reports/1954711Permissions Required
FAQ
What is CVE-2023-32074?
CVE-2023-32074 is a vulnerability with a CVSS score of 8.0 (HIGH). user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2
How severe is CVE-2023-32074?
CVE-2023-32074 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-32074?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud User Oidc.