Vulnerability CVE-2023-32074


Published: 2023-05-25   Modified: 2023-05-26

Description:
user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2

 References:
https://github.com/nextcloud/user_oidc/pull/615
https://hackerone.com/reports/1954711
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x8mc-84wj-rf34

Copyright 2023, cxsecurity.com

 

Back to Top