Description


A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.

Related CPE's


a

nextcloud

nextcloud_server

3

References


https://hackerone.com/reports/486693

Permissions RequiredThird Party Advisory

Weaknesses



CWE-384


CWE-384

CVSS impact metrics


CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

5.9 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2020-02-04T20:15:11.793

5 years ago

Last modified

2020-03-24T16:13:37.170

5 years ago