Nextcloud User OIDC
cpe:2.3:a:nextcloud:user_oidc:*:*:*:*:*:*:*
- >= 1.3.6
- >= 5.0.3
- >= 6.1.0
- >= 6.3.0
- >= 8.0.0
A vulnerability exists in the Nextcloud User OIDC app, specifically in versions 1.3.6 prior to 8.4.0, as well as 5.0.3, 6.1.0, and 6.3.0. The issue arises from an improper check in the LdapService, which allowed deleted LDAP users to still authenticate with the user OIDC app. This vulnerability has been patched in version 8.4.0.
Exploitation of this vulnerability allowed deleted LDAP users to authenticate with the Nextcloud User OIDC app, potentially leading to unauthorized access or actions under the identity of the deleted user.
Users of the Nextcloud User OIDC app are advised to upgrade to version 8.4.0. If an immediate upgrade is not possible, the app can be temporarily disabled.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.