CVE-2019-15612: Medium severity nextcloud server vulnerability
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15612?
CVE-2019-15612 has a medium severity rating as it affects 2FA logins when a user's password is reset.
How do I fix CVE-2019-15612?
To fix CVE-2019-15612, upgrade Nextcloud Server to version 15.0.3 or later, or version 14.0.8 or later, or version 13.0.12 or later.
Which versions of Nextcloud Server are affected by CVE-2019-15612?
CVE-2019-15612 affects Nextcloud Server versions 15.0.0 to 15.0.2, 14.0.0 to 14.0.7, and 13.0.0 to 13.0.11.
What type of attack does CVE-2019-15612 enable?
CVE-2019-15612 potentially allows an attacker to gain unauthorized access using an unexpired 2FA session after a password reset.
Is it necessary to implement any additional security measures for CVE-2019-15612?
While fixing CVE-2019-15612 by updating your software is crucial, it is also advisable to review and strengthen your overall security practices for enhanced protection.