CVE-2023-39953: Issuer not verified from obtained token in user_oidc
useroidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, missing verification of the issuer would have allowed an attacker to perform a man-in-the-middle attack returning corrupted or known token they also have access to. useroidc 1.3.3 contains a patch. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-39953?
CVE-2023-39953 is a vulnerability in the user_oidc plugin for Nextcloud, which allowed an attacker to perform a man-in-the-middle attack by bypassing issuer verification.
What is the severity of CVE-2023-39953?
CVE-2023-39953 has a severity keyword of medium and a severity value of 4.8.
How does CVE-2023-39953 affect Nextcloud?
CVE-2023-39953 affects Nextcloud instances that have the user_oidc plugin installed and are running versions prior to 1.3.3.
How can I fix CVE-2023-39953?
To fix CVE-2023-39953, you should update the user_oidc plugin to version 1.3.3 or later.
Where can I find more information about CVE-2023-39953?
More information about CVE-2023-39953 can be found in the following references: [link1], [link2], [link3].