CVE-2018-3761
HIGHNextcloud Server < 12.0.8 - Improper Authentication on OAuth2 Token Endpoint
Title source: llmDescription
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://hackerone.com/reports/343111
Broken Link, Vendor Advisory x_refsource_confirm
https://nextcloud.com/security/advisory/?id=nc-sa-2018-003
Scores
CVSS v3
8.1
EPSS
0.0060
EPSS Percentile
69.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Details
CWE
CWE-287
Status
published
Products (1)
nextcloud/nextcloud_server
< 12.0.8
Published
Jul 05, 2018
Tracked Since
Feb 18, 2026