CVE-2018-3761
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
05/07/2018
Last modified:
28/02/2023
Description
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* | 12.0.8 (excluding) | |
| cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* | 13.0.0 (including) | 13.0.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



