CVE-2023-45151: OAuth2 client_secret stored in plain text in the Nextcloud database
Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who has gained access to the server to potentially elevate their privilege. This issue has been addressed and users are recommended to upgrade their Nextcloud Server to version 25.0.8, 26.0.3 or 27.0.1. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Nextcloud server vulnerability?
The vulnerability ID for this Nextcloud server vulnerability is CVE-2023-45151.
What is the severity of CVE-2023-45151?
The severity of CVE-2023-45151 is high.
What is the affected software for CVE-2023-45151?
The affected software for CVE-2023-45151 is Nextcloud Server versions 25.0.0 through 25.0.8, Nextcloud Server versions 26.0.0 through 26.0.3, and Nextcloud Server version 27.0.0.
How can an attacker exploit CVE-2023-45151?
An attacker can exploit CVE-2023-45151 by gaining access to the Nextcloud server and obtaining plaintext OAuth2 tokens.
How can I fix CVE-2023-45151?
To fix CVE-2023-45151, users are recommended to upgrade their Nextcloud Server to a version that addresses the issue.