CVE-2019-15612: Medium severity nextcloud server vulnerability

Published Feb 4, 2020
·
Updated

A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.

Affected Software

3 affected components
Nextcloud Server>=13.0.0<13.0.11
Nextcloud Server>=14.0.0<14.0.7
Nextcloud Server>=15.0.0<15.0.3

Event History

Feb 4, 2020
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
DescriptionWeakness

Frequently Asked Questions

1

What is the severity of CVE-2019-15612?

CVE-2019-15612 has a medium severity rating as it affects 2FA logins when a user's password is reset.

2

How do I fix CVE-2019-15612?

To fix CVE-2019-15612, upgrade Nextcloud Server to version 15.0.3 or later, or version 14.0.8 or later, or version 13.0.12 or later.

3

Which versions of Nextcloud Server are affected by CVE-2019-15612?

CVE-2019-15612 affects Nextcloud Server versions 15.0.0 to 15.0.2, 14.0.0 to 14.0.7, and 13.0.0 to 13.0.11.

4

What type of attack does CVE-2019-15612 enable?

CVE-2019-15612 potentially allows an attacker to gain unauthorized access using an unexpired 2FA session after a password reset.

5

Is it necessary to implement any additional security measures for CVE-2019-15612?

While fixing CVE-2019-15612 by updating your software is crucial, it is also advisable to review and strengthen your overall security practices for enhanced protection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203