WebAuthn Improper Configuration in Nextcloud Server 19.0.1
CVE-2020-8236
6.8MEDIUM
What is CVE-2020-8236?
In Nextcloud Server version 19.0.1, a configuration flaw related to passwordless WebAuthn allows users to mistakenly believe they are experiencing two-factor verification. It prompts for a PIN without properly validating it, creating a deceptive perception of security for the users.
Affected Version(s)
Nextcloud Server 19.0.2