CVE-2024-37886 impacts the Nextcloud user_oidc app, an OpenID Connect user backend, allowing an attacker to potentially trick the app into accepting an improperly signed request. This vulnerability has a CVSS score of 4.7 (Medium), indicating a network attack vector with low complexity, requiring user interaction, and potentially leading to low integrity impact. While no active exploitation, public exploit code, or significant community discussion has been observed, users are advised to upgrade the user_oidc app to versions 1.3.5, 2.0.0, 3.0.0, 4.0.0, or 5.0.0 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.5CPE matchmatch criteria | cpe:2.3:a:nextcloud:user_oidc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.