OAuth2 client secrets were stored in a recoverable way
Package
Server
(Nextcloud)
Affected versions
>= 28.0.0, >= 29.0.0
Patched versions
28.0.10, 29.0.7
Server
(Nextcloud Enterprise)
>= 27.0.0, >= 28.0.0, >= 29.0.0
27.1.11.8, 28.0.10, 29.0.7
Impact
The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them.
Patches
It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7
It is recommended that the Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7
Workarounds
References
For more information
If you have any questions or comments about this advisory: