PT-2022-24909 · Nextcloud · User Oidc
Lauritz
·
Published
2022-11-25
·
Updated
2022-12-01
·
CVE-2022-39339
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
user oidc versions prior to 1.2.1
Description
The issue concerns the user oidc OpenID Connect user backend for Nextcloud, where sensitive information such as OIDC client credentials and tokens are sent in plain text over HTTP without TLS in versions prior to 1.2.1. This allows any malicious actor with access to monitor user traffic to potentially compromise account security.
Recommendations
For versions prior to 1.2.1, upgrade to user oidc v1.2.1 to address the issue.
As a temporary workaround for users unable to upgrade, use HTTPS to access Nextcloud and set an HTTPS discovery URL in the provider settings within the Nextcloud OIDC admin settings.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
User Oidc