CVE-2019-12902: Medium severity pydio vulnerability
Published Jun 19, 2019
·Updated
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.
Affected Software
1 affected component
Pydio Cells<1.5.0
Event History
Jun 19, 2019
CVE Published
via MITRE·11:05 PM
Data Sourced
via MITRE·11:05 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12902?
CVE-2019-12902 is a vulnerability in Pydio Cells before 1.5.0 that allows a new user to restore the deleted user's data.
2
What is the severity of CVE-2019-12902?
The severity of CVE-2019-12902 is medium with a CVSS score of 6.5.
3
How does CVE-2019-12902 affect Pydio Cells?
CVE-2019-12902 affects Pydio Cells versions up to and excluding 1.5.0.
4
How can I fix CVE-2019-12902?
To fix CVE-2019-12902, you should update Pydio Cells to version 1.5.0 or later.
5
Where can I find more information about CVE-2019-12902?
You can find more information about CVE-2019-12902 on the Pydio website and the Loginsoft vulnerability report.