Missing password confirmation when creating app passwords
CVE-2023-39963

8.1HIGH

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
10 August 2023

What is CVE-2023-39963?

A vulnerability in Nextcloud Server allowed attackers who successfully authenticated to steal a session from a logged-in user to create app passwords without needing to confirm the user's password. This flaw impacts several versions of Nextcloud Server and can lead to unauthorized access and actions within the user's account. Patches have been released for specific versions, but users with unpatched systems remain at risk.

Affected Version(s)

security-advisories >= 20.0.0, < 20.0.14.15 < 20.0.0, 20.0.14.15

security-advisories >= 21.0.0, < 21.0.9.13 < 21.0.0, 21.0.9.13

security-advisories >= 22.0.0, < 22.2.10.14 < 22.0.0, 22.2.10.14

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.