Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45926 | user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully authenticating. It is recommended that the Nextcloud User OIDC app is upgraded to 6.1.0. |
Fri, 15 Aug 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nextcloud:user_oidc:*:*:*:*:*:*:*:* |
Fri, 15 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 Nov 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully authenticating. It is recommended that the Nextcloud User OIDC app is upgraded to 6.1.0. | |
| Title | Nextcloud User OIDC has an open redirection when logging in with User OIDC | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-15T18:24:27.739Z
Reserved: 2024-11-11T18:49:23.558Z
Link: CVE-2024-52512
Updated: 2024-11-15T18:24:24.129Z
Status : Analyzed
Published: 2024-11-15T18:15:29.933
Modified: 2025-08-15T13:53:22.120
Link: CVE-2024-52512
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:31:48Z
EUVD