CVE-2023-28848
A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to bypass the state protection as they could just copy the expected state token from the first request to their second request.
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to bypass the state protection as they could just copy the expected state token from the first request to their second request. Users should upgrade user_oidc to 1.3.0 to receive a patch for the issue. No known workarounds are available.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- nextcloud/user oidc
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-52hv-xw32-wf7fVendor Advisory
- https://github.com/nextcloud/user_oidc/pull/580Patch, Vendor Advisory
- https://hackerone.com/reports/1878381Third Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-52hv-xw32-wf7fVendor Advisory
- https://github.com/nextcloud/user_oidc/pull/580Patch, Vendor Advisory
- https://hackerone.com/reports/1878381Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.