CVE-2019-15610: Medium severity nextcloud circles vulnerability
Published Feb 4, 2020
·Updated
Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.
Affected Software
2 affected components
Nextcloud Circles<0.16.11
Nextcloud Circles>=0.16.12<0.17.8
Event History
Feb 4, 2020
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-15610?
CVE-2019-15610 has a medium severity rating due to its potential for unauthorized access.
2
How do I fix CVE-2019-15610?
To fix CVE-2019-15610, upgrade your Circles app to version 0.17.8 or later.
3
What does CVE-2019-15610 affect?
CVE-2019-15610 affects versions of the Circles app in Nextcloud prior to version 0.17.8 and those between 0.16.12 and 0.17.7.
4
What kind of vulnerability is CVE-2019-15610?
CVE-2019-15610 is an authorization issue that allows former members to retain access to a circle even after being removed.
5
Is CVE-2019-15610 exploitable?
Yes, CVE-2019-15610 is exploitable, allowing unauthorized users to access sensitive circle information.