First published: Tue Feb 04 2020(Updated: )
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | >=13.0.0<13.0.11 | |
Nextcloud Nextcloud Server | >=14.0.0<14.0.7 | |
Nextcloud Nextcloud Server | >=15.0.0<15.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.