Vulnerability Description
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Nextcloud | < 2.24.0 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/672623Permissions RequiredThird Party Advisory
- https://nextcloud.com/security/advisory/?id=NC-SA-2019-017Vendor Advisory
- https://hackerone.com/reports/672623Permissions RequiredThird Party Advisory
- https://nextcloud.com/security/advisory/?id=NC-SA-2019-017Vendor Advisory
FAQ
What is CVE-2019-15611?
CVE-2019-15611 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifica...
How severe is CVE-2019-15611?
CVE-2019-15611 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15611?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Nextcloud.