CVE-2026-45278
בינונית 6.1
תיאור (מקור, אנגלית)
Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses the attackers link to log in via user OIDC. This issue has been patched in version 8.2.2.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-7/8/2026
- CWE
- CWE-601
מוצרים מושפעים
nextcloud: user oidc
קישורים
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8wjr… Vendor Advisory
- https://github.com/nextcloud/user_oidc/pull/1273 Issue TrackingPatch
- https://hackerone.com/reports/3464925 Permissions Required