ZeroHour

CVE-2018-3761

CVSS 3.1
8.1 high
EPSS
2%p75
Published
()
Modified
Description

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.

Vendors
nextcloud
Products
nextcloud server
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.