CVE-2023-39954: user_oidc app stores client secret unencrypted in database
useroidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the database can impersonate the Nextcloud server towards linked servers. useroidc 1.3.3 contains a patch. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-39954?
CVE-2023-39954 is a vulnerability in the user_oidc component of Nextcloud that allows an attacker to impersonate the Nextcloud server towards linked servers.
How does CVE-2023-39954 impact Nextcloud?
CVE-2023-39954 allows an attacker with read access to a database snapshot to impersonate the Nextcloud server.
What is the severity of CVE-2023-39954?
CVE-2023-39954 has a severity rating of 8.1 (High).
How can an attacker exploit CVE-2023-39954?
An attacker can exploit CVE-2023-39954 by obtaining read access to a snapshot of the database.
Is there a fix available for CVE-2023-39954?
Yes, a fix for CVE-2023-39954 is available in user_oidc version 1.3.3.