CVE-2024-37886

MEDIUM

Nextcloud user_oidc < 1.3.5 - Improper Verification of Cryptographic Signature

Title source: llm
STIX 2.1

Description

user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.5, 2.0.0, 3.0.0, 4.0.0 or 5.0.0.

References (3)

Core 3
Core References
Issue Tracking, Patch x_refsource_misc
https://github.com/nextcloud/user_oidc/pull/715
Issue Tracking x_refsource_misc
https://hackerone.com/reports/1878391

Scores

CVSS v3 5.4
EPSS 0.0024
EPSS Percentile 14.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (1)
nextcloud/user_oidc < 1.3.5
Published Jun 14, 2024
Tracked Since Feb 18, 2026