Bug ID 1218981
Summary VUL-0: CVE-2024-22403: nextcloud: OAuth codes did not expire
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/391700/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee ecsos@schirra.net
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC andrea.mattiazzo@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

Nextcloud server is a self hosted personal cloud system. In affected versions
OAuth codes did not expire. When an attacker would get access to an
authorization code they could authenticate at any time using the code. As of
version 28.0.0 OAuth codes are invalidated after 10 minutes and will no longer
be authenticated. To exploit this vulnerability an attacker would need to
intercept an OAuth code from a user session. It is recommended that the
Nextcloud Server is upgraded to 28.0.0. There are no known workarounds for this
vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-22403
https://www.cve.org/CVERecord?id=CVE-2024-22403
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wppc-f5g8-vx36
https://hackerone.com/reports/1784162

Patch:
https://github.com/nextcloud/server/pull/40766


You are receiving this mail because: