First published: Thu Aug 10 2023(Updated: )
user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the database can impersonate the Nextcloud server towards linked servers. user_oidc 1.3.3 contains a patch. No known workarounds are available.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud User Oidc | >=1.0.0<1.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39954 is a vulnerability in the user_oidc component of Nextcloud that allows an attacker to impersonate the Nextcloud server towards linked servers.
CVE-2023-39954 allows an attacker with read access to a database snapshot to impersonate the Nextcloud server.
CVE-2023-39954 has a severity rating of 8.1 (High).
An attacker can exploit CVE-2023-39954 by obtaining read access to a snapshot of the database.
Yes, a fix for CVE-2023-39954 is available in user_oidc version 1.3.3.