Authentication Bypass Vulnerability in Nextcloud Server
CVE-2019-15617

5.4MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
4 February 2020

What is CVE-2019-15617?

A vulnerability in Nextcloud Server 17.0.0 arises from a missing validation check, enabling unauthorized users to add an alternative second factor during the login process. This flaw poses a risk of account takeover, as attackers can exploit it to gain access to sensitive data without proper authorization. Organizations using this version of Nextcloud Server should take immediate measures to mitigate this risk by updating to patched versions.

Affected Version(s)

Nextcloud Server 17.0.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-15617 : Authentication Bypass Vulnerability in Nextcloud Server