Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36570 | user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that the OpenID Connect user backend is upgraded to 3.0.0 (Nextcloud 20-23), 4.0.0 (Nexcloud 24) or 5.0.0 (Nextcloud 25-28). |
Thu, 14 Aug 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:nextcloud:user_oidc:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T03:50:55.709Z
Reserved: 2024-06-05T20:10:46.498Z
Link: CVE-2024-37312
Updated: 2024-06-14T17:15:44.214Z
Status : Analyzed
Published: 2024-06-14T15:15:51.197
Modified: 2026-06-17T07:38:07.303
Link: CVE-2024-37312
No data.
OpenCVE Enrichment
No data.
-
CWE-284
Improper Access Control
- NVD-CWE-noinfo
EUVD