First published: Tue Feb 04 2020(Updated: )
Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Circles | <0.16.11 | |
Nextcloud Circles | >=0.16.12<0.17.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.