Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36870 | user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.5, 2.0.0, 3.0.0, 4.0.0 or 5.0.0. |
Thu, 14 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nextcloud:user_oidc:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T03:57:40.025Z
Reserved: 2024-06-10T19:54:41.360Z
Link: CVE-2024-37886
Updated: 2024-06-15T20:26:23.078Z
Status : Analyzed
Published: 2024-06-14T16:15:13.800
Modified: 2026-06-17T07:38:59.370
Link: CVE-2024-37886
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:00:46Z
-
CWE-347
Improper Verification of Cryptographic Signature
EUVD