Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frc3-rhfw-jxf5

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.

EPSS

Процентиль: 69%
0.00628
Низкий

8.1 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
nvd
почти 7 лет назад

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.

CVSS3: 8.1
debian
почти 7 лет назад

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authent ...

suse-cvrf
почти 7 лет назад

Security update for nextcloud

EPSS

Процентиль: 69%
0.00628
Низкий

8.1 High

CVSS3

Дефекты

CWE-287