CVE-2018-3761: High severity nextcloud server vulnerability
Published Jul 5, 2018
·Updated
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.
Affected Software
2 affected components
Nextcloud Server<12.0.8
Nextcloud Server>=13.0.0<13.0.3
Event History
Jul 5, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-3761?
CVE-2018-3761 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2018-3761?
To fix CVE-2018-3761, upgrade Nextcloud Server to version 12.0.8 or later, or version 13.0.3 or later.
3
What type of vulnerability is CVE-2018-3761?
CVE-2018-3761 is categorized as an improper authentication vulnerability on the OAuth2 token endpoint.
4
Which versions of Nextcloud Server are affected by CVE-2018-3761?
Nextcloud Server versions prior to 12.0.8 and between 13.0.0 and 13.0.3 are affected by CVE-2018-3761.
5
What can attackers potentially exploit in CVE-2018-3761?
Attackers can potentially exploit CVE-2018-3761 to obtain new tokens if the OAuth2 client is partially compromised.