← Back to CVE List

CVE-2018-3761

Published: 2018-07-05T16:29Z
Last Modified: 2024-11-21T04:06Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt