CVE-2023-39954Missing Encryption of Sensitive Data in User Oidc

Severity
8.1HIGHNVD
CNA3.8
EPSS
0.4%
top 38.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 10

Description

user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the database can impersonate the Nextcloud server towards linked servers. user_oidc 1.3.3 contains a patch. No known workarounds are available.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

NVDnextcloud/user_oidc1.0.01.3.3
CVEListV5nextcloud/security-advisories>= 1.0.0, < 1.3.3

Patches

🔴Vulnerability Details

1
CVEList
user_oidc app stores client secret unencrypted in database2023-08-10
CVE-2023-39954 — Missing Encryption of Sensitive Data | cvebase