CVE-2024-37312 - CVE House
Back to Database
Status published Medium CVE-2024-37312

Nextcloud user_oidc app's ID4me feature is available even when disabled

Vulnerability Description

user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that the OpenID Connect user backend is upgraded to 3.0.0 (Nextcloud 20-23), 4.0.0 (Nexcloud 24) or 5.0.0 (Nextcloud 25-28).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-37312

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

security-advisories
Vulnerable Versions:
<= 1.3.6

Timeline

Official Publish: June 14th, 2024
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses (CWE)