CVE-2018-3761

HIGH

Nextcloud Server < 12.0.8 - Improper Authentication on OAuth2 Token Endpoint

Title source: llm
STIX 2.1

Description

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://hackerone.com/reports/343111
Broken Link, Vendor Advisory x_refsource_confirm
https://nextcloud.com/security/advisory/?id=nc-sa-2018-003

Scores

CVSS v3 8.1
EPSS 0.0060
EPSS Percentile 69.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Details

CWE
CWE-287
Status published
Products (1)
nextcloud/nextcloud_server < 12.0.8
Published Jul 05, 2018
Tracked Since Feb 18, 2026