CVE-2024-52512
- EPSS 0.07%
- Published 15.11.2024 18:15:29
- Last modified 15.08.2025 13:53:22
user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully authenticating. It is recommended that the Nextcloud User OIDC app is ...
CVE-2024-37886
- EPSS 0.59%
- Published 14.06.2024 16:15:13
- Last modified 14.08.2025 19:03:04
user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.5, 2.0...
CVE-2024-37312
- EPSS 0.34%
- Published 14.06.2024 15:15:51
- Last modified 14.08.2025 19:18:22
user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that ...
CVE-2023-39954
- EPSS 0.37%
- Published 10.08.2023 15:15:09
- Last modified 21.11.2024 08:16:06
user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the database can impersonate the Next...
CVE-2023-39953
- EPSS 0.49%
- Published 10.08.2023 14:15:15
- Last modified 21.11.2024 08:16:06
user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, missing verification of the issuer would have allowed an attacker to perform a man-in-the-middle atta...
CVE-2023-32074
- EPSS 0.31%
- Published 25.05.2023 23:15:09
- Last modified 21.11.2024 08:02:39
user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2
CVE-2023-28848
- EPSS 0.43%
- Published 04.04.2023 13:15:08
- Last modified 21.11.2024 07:56:09
user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to bypass the state protection as they could just copy the expected state t...