CVE-2019-15612

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/02/2020
Last modified:
24/03/2020

Description

A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 13.0.0 (including) 13.0.11 (excluding)
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 14.0.0 (including) 14.0.7 (excluding)
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 15.0.0 (including) 15.0.3 (excluding)