CVE-2019-15624: Input Validation
Published Feb 4, 2020
·Updated
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
Affected Software
4 affected components
Nextcloud NextCloud Server<14.0.11
Nextcloud NextCloud Server>=15.0.0<15.0.8
openSUSE Backports=sle-15-sp1
SUSE SUSE Linux Enterprise Server=12
Event History
Feb 4, 2020
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-15624?
CVE-2019-15624 is a vulnerability in Nextcloud Server 15.0.7 that allows group admins to create users with IDs of system folders.
2
How severe is CVE-2019-15624?
CVE-2019-15624 has a severity score of 4.9, which is considered medium.
3
Which software versions are affected by CVE-2019-15624?
Nextcloud Server versions up to and including 14.0.11, as well as versions from 15.0.0 to 15.0.8, are affected by CVE-2019-15624.
4
How can I fix CVE-2019-15624?
Update Nextcloud Server to version 15.0.9 or later to fix CVE-2019-15624.
5
Where can I find more information about CVE-2019-15624?
You can find more information about CVE-2019-15624 at the following references: [link1], [link2], [link3].