VulnerabilityAnalyzed
CVE-2024-37886
An attacker could potentially trick the app into accepting a request that is not signed by the correct server.
MEDIUM 4.7EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.5, 2.0.0, 3.0.0, 4.0.0 or 5.0.0.
- CVSS 3.1
- 4.7 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- nextcloud/user oidc
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vw5h-29xf-g55gVendor Advisory
- https://github.com/nextcloud/user_oidc/pull/715Issue Tracking, Patch
- https://hackerone.com/reports/1878391Issue Tracking
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vw5h-29xf-g55gVendor Advisory
- https://github.com/nextcloud/user_oidc/pull/715Issue Tracking, Patch
- https://hackerone.com/reports/1878391Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.