VulnerabilityModified
CVE-2019-15611
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
MEDIUM 4.9EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-657
- Affected
- nextcloud/nextcloud
- Source
- support@hackerone.com
References
- https://hackerone.com/reports/672623Permissions Required, Third Party Advisory
- https://nextcloud.com/security/advisory/?id=NC-SA-2019-017Vendor Advisory
- https://hackerone.com/reports/672623Permissions Required, Third Party Advisory
- https://nextcloud.com/security/advisory/?id=NC-SA-2019-017Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.