Back to Database
Status published
Low
CVE-2024-52512
Nextcloud User OIDC has an open redirection when logging in with User OIDC
Vulnerability Description
user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully authenticating. It is recommended that the Nextcloud User OIDC app is upgraded to 6.1.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-52512
Credits & Attribution
No credits recorded in the NVD database.
References
More from nextcloud
View All →CVE-2025-66558
Nextcloud Twofactor WebAuthn app was updated based on public key
Low
3.1
CVE-2025-66557
Nextcloud Deck app allowed user with "Can share" permission to modify permissions of other non-owners
Medium
5.4
CVE-2025-66556
Nextcloud talk allows participants to blindly delete poll drafts of other users by ID
Low
3.5
CVE-2025-66554
Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field
Low
3.5
CVE-2025-66553
Nextcloud Tables app allowed users to view columns metadata information of any table
Medium
4.3
Affected Vendor
nextcloud
View all reports →Affected Software
security-advisories
Vulnerable Versions:
>= 6.0.0, < 6.1.0
Timeline
Official Publish:
November 15th, 2024
Last Modified:
November 15th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N