CVE-2019-15612

A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
PHYSICAL
LOW
LOW
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
hackeroneCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
nextcloudnextcloud_server
13.0.0 ≤
𝑥
< 13.0.11
nextcloudnextcloud_server
14.0.0 ≤
𝑥
< 14.0.7
nextcloudnextcloud_server
15.0.0 ≤
𝑥
< 15.0.3
𝑥
= Vulnerable software versions