CVE-2023-32074
CVSS V2 None
CVSS V3 None
Description
user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2
Overview
- CVE ID
- CVE-2023-32074
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-05-25T22:59:27.860Z
- Last Modified Date
- 2023-05-25T22:59:27.860Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x8mc-84wj-rf34 | x_refsource_CONFIRM |
https://github.com/nextcloud/user_oidc/pull/615 | x_refsource_MISC |
https://hackerone.com/reports/1954711 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-32074 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32074 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 11:22:44 | Added to TrackCVE |