HomeNextcloudCVE-2024-52512

CVE-2024-52512

LOW
3.3CVSS
Published: 2024-11-15
Updated: 2025-08-15
AI Analysis

Description

user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully authenticating. It is recommended that the Nextcloud User OIDC app is upgraded to 6.1.0.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Vector
local
Complexity
low
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
low
Integrity
none
Availability
none
Weaknesses
CWE-601

Metadata

Primary Vendor
NEXTCLOUD
Published
11/15/2024
Last Modified
8/15/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

nextcloud : user_oidc

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-52512 | LOW Severity | CVEDatabase.com | CVEDatabase.com