PT-2023-27171 · Nextcloud+1 · Nextcloud+1

Rullzer

·

Publicado

2023-08-10

·

Atualizado

2023-08-16

·

CVE-2023-39954

CVSS v3.1

3.8

Baixa

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions user oidc versions 1.0.0 through 1.3.2
Description The issue affects the user oidc module, which provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. An attacker with at least read access to a snapshot of the database can impersonate the Nextcloud server towards linked servers.
Recommendations For versions 1.0.0 through 1.3.2, update to version 1.3.3, which contains a patch for the issue. As a temporary workaround, consider restricting access to the database to minimize the risk of exploitation.

Exploit

Correção

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-39954
GHSA-3F92-5C8P-F6GQ

Produtos afetados

Nextcloud
User Oidc