PT-2022-24909 · Nextcloud · User Oidc

Lauritz

·

Published

2022-11-25

·

Updated

2022-12-01

·

CVE-2022-39339

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions user oidc versions prior to 1.2.1
Description The issue concerns the user oidc OpenID Connect user backend for Nextcloud, where sensitive information such as OIDC client credentials and tokens are sent in plain text over HTTP without TLS in versions prior to 1.2.1. This allows any malicious actor with access to monitor user traffic to potentially compromise account security.
Recommendations For versions prior to 1.2.1, upgrade to user oidc v1.2.1 to address the issue. As a temporary workaround for users unable to upgrade, use HTTPS to access Nextcloud and set an HTTPS discovery URL in the provider settings within the Nextcloud OIDC admin settings.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-39339
GHSA-2VFF-CQ8H-CHHG

Affected Products

User Oidc