CVE-2023-39954

    Dashboard / Vulnerabilities / CVE-2023-39954

    CVE-2023-39954

    Published: 10 Aug 2023Last Modified: 12 Aug 2026

    Summary: user_oidc app stores client secret unencrypted in database

    Details: user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the database can impersonate the Nextcloud server towards linked servers. user_oidc 1.3.3 contains a patch. No known workarounds are available.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 2b27bd81899d8607f82ad41c2831bef91db835a5

    Affected versions

    v1.2.0
    v1.2.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-39954 | CVE-DB