Missing password confirmation when creating app passwords
CVE-2023-39963
8.1HIGH
What is CVE-2023-39963?
A vulnerability in Nextcloud Server allowed attackers who successfully authenticated to steal a session from a logged-in user to create app passwords without needing to confirm the user's password. This flaw impacts several versions of Nextcloud Server and can lead to unauthorized access and actions within the user's account. Patches have been released for specific versions, but users with unpatched systems remain at risk.
Affected Version(s)
security-advisories >= 20.0.0, < 20.0.14.15 < 20.0.0, 20.0.14.15
security-advisories >= 21.0.0, < 21.0.9.13 < 21.0.0, 21.0.9.13
security-advisories >= 22.0.0, < 22.2.10.14 < 22.0.0, 22.2.10.14