PT-2022-24908 · Nextcloud+1 · User Oidc+1

Lauritz

·

Published

2022-11-25

·

Updated

2022-12-01

·

CVE-2022-39338

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions user oidc versions prior to 1.2.1
Description The issue is related to the improper validation of discovery URLs in the user oidc OpenID Connect user backend for Nextcloud, potentially leading to a stored cross-site scripting attack vector. The impact is limited due to the restrictive Content Security Policy (CSP) applied on this endpoint. This vulnerability has only been shown to be exploitable in the Safari web browser.
Recommendations For versions prior to 1.2.1, upgrade to version 1.2.1 to address the issue. If an upgrade is not possible, advise users to avoid using the Safari web browser as a temporary mitigation measure.

Exploit

Fix

XSS

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-39338
GHSA-5FPW-795H-RG57

Affected Products

Safari
User Oidc