user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully authenticating. It is recommended that the Nextcloud User OIDC app is upgraded to 6.1.0.
References
Link | Resource |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-784j-x2g5-4g7q | Vendor Advisory |
https://github.com/nextcloud/user_oidc/commit/c923428d51972f6d04636c6accbecdec0c1b88e9 | Patch |
https://github.com/nextcloud/user_oidc/pull/961 | Issue Tracking VDB Entry |
https://hackerone.com/reports/2720030 | Third Party Advisory |
Configurations
History
15 Aug 2025, 13:53
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:nextcloud:user_oidc:*:*:*:*:*:*:*:* | |
References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-784j-x2g5-4g7q - Vendor Advisory | |
References | () https://github.com/nextcloud/user_oidc/commit/c923428d51972f6d04636c6accbecdec0c1b88e9 - Patch | |
References | () https://github.com/nextcloud/user_oidc/pull/961 - Issue Tracking, VDB Entry | |
References | () https://hackerone.com/reports/2720030 - Third Party Advisory | |
First Time |
Nextcloud user Oidc
Nextcloud |
18 Nov 2024, 17:11
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Nov 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-15 18:15
Updated : 2025-08-15 13:53
NVD link : CVE-2024-52512
Mitre link : CVE-2024-52512
CVE.ORG link : CVE-2024-52512
JSON object : View
Products Affected
nextcloud
- user_oidc
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')