CVE-2019-15615: Medium severity nextcloud vulnerability
Published Feb 4, 2020
·Updated
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.
Affected Software
1 affected component
Nextcloud Nextcloud android<=3.9.0
Event History
Feb 4, 2020
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-15615.
2
What is the severity of CVE-2019-15615?
The severity of CVE-2019-15615 is medium with a CVSS score of 6.1.
3
What software versions are affected by CVE-2019-15615?
Nextcloud Android App version 3.9.0 is affected by CVE-2019-15615.
4
How does CVE-2019-15615 bypass the lock protection?
CVE-2019-15615 bypasses the lock protection by incorrectly checking the system time in the Android App 3.9.0 when changing the time of the system to the past.
5
Where can I find more information about CVE-2019-15615?
You can find more information about CVE-2019-15615 on the Nextcloud security advisory (NC-SA-2020-004) and the HackerOne report (ID: 747726).