Vulnerability record · CVE-2024-37312 · published 14 June 2024
CVE-2024-37312: Nextcloud user oidc improper access control vulnerability
Nextcloud · User Oidc
user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that the OpenID Connect user backend is upgraded to 3.0.0 (Nextcloud 20-23), 4.0.0 (Nexcloud 24) or 5.0.0 (Nextcloud 25-28).
Description
user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that the OpenID Connect user backend is upgraded to 3.0.0 (Nextcloud 20-23), 4.0.0 (Nexcloud 24) or 5.0.0 (Nextcloud 25-28).
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vw7g-959g-vj6q | Vendor Advisory |
| https://github.com/nextcloud/user_oidc/commit/9f68a716ecd264160a7c098b8840313f1ac855f2 | Patch |
| https://hackerone.com/reports/2376929 | ExploitThird Party Advisory |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vw7g-959g-vj6q | Vendor Advisory |
| https://github.com/nextcloud/user_oidc/commit/9f68a716ecd264160a7c098b8840313f1ac855f2 | Patch |
| https://hackerone.com/reports/2376929 | ExploitThird Party Advisory |
Track CVE-2024-37312 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-37312), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.