Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
References
Link | Resource |
---|---|
https://nextcloud.com/security/advisory/?id=NC-SA-2019-017 | Vendor Advisory |
https://hackerone.com/reports/672623 | Permissions Required Third Party Advisory |
Configurations
Information
Published : 2020-02-04 12:15
Updated : 2020-02-11 08:59
NVD link : CVE-2019-15611
Mitre link : CVE-2019-15611
JSON object : View
CWE
Products Affected
nextcloud
- nextcloud