Bug ID 1162761
Summary VUL-1: CVE-2019-15612: A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.0
Hardware Other
URL https://smash.suse.de/issue/252403/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee ecsos@schirra.net
Reporter rfrohl@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2019-15612

A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly
expired when the password of the user is reset.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15612
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15612
https://nextcloud.com/security/advisory/?id=NC-SA-2020-001
https://hackerone.com/reports/486693


You are receiving this mail because: