user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x8mc-84wj-rf34 | vendor advisory |
https://github.com/nextcloud/user_oidc/pull/615 | patch issue tracking |
https://hackerone.com/reports/1954711 | permissions required |