First published: Tue Feb 04 2020(Updated: )
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud | <=3.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-15615.
The severity of CVE-2019-15615 is medium with a CVSS score of 6.1.
Nextcloud Android App version 3.9.0 is affected by CVE-2019-15615.
CVE-2019-15615 bypasses the lock protection by incorrectly checking the system time in the Android App 3.9.0 when changing the time of the system to the past.
You can find more information about CVE-2019-15615 on the Nextcloud security advisory (NC-SA-2020-004) and the HackerOne report (ID: 747726).