{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"important"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2018-3761","title":"Title"},{"category":"description","text":"Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2018-3761","url":"https://www.suse.com/security/cve/CVE-2018-3761"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1100343 for CVE-2018-3761","url":"https://bugzilla.suse.com/1100343"},{"category":"external","summary":"SUSE Bug 1100344 for CVE-2018-3761","url":"https://bugzilla.suse.com/1100344"},{"category":"external","summary":"Advisory link for openSUSE-SU-2018:1924-1","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RSHDIDRMLM7RS77R7KSNDMLMB2B2ZALH/#RSHDIDRMLM7RS77R7KSNDMLMB2B2ZALH"}],"title":"SUSE CVE CVE-2018-3761","tracking":{"current_release_date":"2025-03-15T12:41:29Z","generator":{"date":"2023-02-15T04:33:04Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2018-3761","initial_release_date":"2023-02-15T04:33:04Z","revision_history":[{"date":"2023-02-15T04:33:04Z","number":"2","summary":"Current version"},{"date":"2023-12-08T04:15:45Z","number":"3","summary":"Current version"},{"date":"2023-12-09T02:59:21Z","number":"4","summary":"Current version"},{"date":"2025-01-01T08:02:12Z","number":"5","summary":"Current version"},{"date":"2025-02-18T07:17:20Z","number":"6","summary":"Current version"},{"date":"2025-03-15T12:41:29Z","number":"7","summary":"Current version"}],"status":"interim","version":"7"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"openSUSE Leap 15.0","product":{"name":"openSUSE Leap 15.0","product_id":"openSUSE Leap 15.0","product_identification_helper":{"cpe":"cpe:/o:opensuse:leap:15.0"}}},{"category":"product_version","name":"nextcloud-13.0.4-lp150.2.3.1","product":{"name":"nextcloud-13.0.4-lp150.2.3.1","product_id":"nextcloud-13.0.4-lp150.2.3.1","product_identification_helper":{"purl":"pkg:rpm/suse/nextcloud@13.0.4-lp150.2.3.1"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"nextcloud-13.0.4-lp150.2.3.1 as component of openSUSE Leap 15.0","product_id":"openSUSE Leap 15.0:nextcloud-13.0.4-lp150.2.3.1"},"product_reference":"nextcloud-13.0.4-lp150.2.3.1","relates_to_product_reference":"openSUSE Leap 15.0"}]},"vulnerabilities":[{"cve":"CVE-2018-3761","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2018-3761"}],"notes":[{"category":"general","text":"Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.","title":"CVE description"}],"product_status":{"recommended":["openSUSE Leap 15.0:nextcloud-13.0.4-lp150.2.3.1"]},"references":[{"category":"external","summary":"CVE-2018-3761","url":"https://www.suse.com/security/cve/CVE-2018-3761"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1100343 for CVE-2018-3761","url":"https://bugzilla.suse.com/1100343"},{"category":"external","summary":"SUSE Bug 1100344 for CVE-2018-3761","url":"https://bugzilla.suse.com/1100344"},{"category":"external","summary":"Advisory link for openSUSE-SU-2018:1924-1","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RSHDIDRMLM7RS77R7KSNDMLMB2B2ZALH/#RSHDIDRMLM7RS77R7KSNDMLMB2B2ZALH"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["openSUSE Leap 15.0:nextcloud-13.0.4-lp150.2.3.1"]}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","version":"3.1"},"products":["openSUSE Leap 15.0:nextcloud-13.0.4-lp150.2.3.1"]}],"threats":[{"category":"impact","date":"2018-07-05T19:26:57Z","details":"important"}],"title":"CVE-2018-3761"}]}