First published: Thu May 25 2023(Updated: )
user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud User Oidc | <1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32074 is a vulnerability in the user_oidc app in Nextcloud, which is an OpenID Connect user backend. It allows for authentication to be bypassed or broken.
CVE-2023-32074 has a severity level of critical, with a severity value of 9.
To fix CVE-2023-32074, it is recommended to upgrade the user_oidc app in Nextcloud to version 1.3.2.
More information about CVE-2023-32074 can be found in the Nextcloud user_oidc GitHub pull request #615, HackerOne report #1954711, and the Nextcloud security advisories page GHSA-x8mc-84wj-rf34.
The CWE (Common Weakness Enumeration) of CVE-2023-32074 is 307, which refers to Improper Restriction of Excessive Authentication Attempts.