PT-2023-27170 · Nextcloud · Nextcloud+1

Rullzer

·

Published

2023-08-10

·

Updated

2023-08-16

·

CVE-2023-39953

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions user oidc versions 1.0.0 through 1.3.2
Description The issue is related to the missing verification of the issuer in the user oidc module for Nextcloud, allowing an attacker to perform a man-in-the-middle attack by returning corrupted or known tokens they have access to.
Recommendations For versions prior to 1.3.3, update to version 1.3.3, which contains a patch for the issue. As a temporary workaround, consider restricting access to the OIDC connect user backend until the patch is applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-39953
GHSA-XX3H-V363-Q36J

Affected Products

Nextcloud
User Oidc