CVE-2023-45151

MEDIUM

Nextcloud Server < 25.0.8 - Cleartext Storage of OAuth2 Tokens

Title source: llm
STIX 2.1

Description

Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who has gained access to the server to potentially elevate their privilege. This issue has been addressed and users are recommended to upgrade their Nextcloud Server to version 25.0.8, 26.0.3 or 27.0.1. There are no known workarounds for this vulnerability.

References (3)

Core 3
Core References
Issue Tracking, Patch x_refsource_misc
https://github.com/nextcloud/server/pull/38398
Permissions Required x_refsource_misc
https://hackerone.com/reports/1994324

Scores

CVSS v3 6.5
EPSS 0.0069
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-312
Status published
Products (2)
nextcloud/nextcloud_server 27.0.0 (2 CPE variants)
nextcloud/nextcloud_server 25.0.0 - 25.0.8 (2 CPE variants)
Published Oct 16, 2023
Tracked Since Feb 18, 2026