CVE-2019-15612: Nextcloud Server
Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
Affected products
- Nextcloud Nextcloud Server: from 13.0.0, before 13.0.11 (fixed in 13.0.11); from 14.0.0, before 14.0.7 (fixed in 14.0.7); from 15.0.0, before 15.0.3 (fixed in 15.0.3)
Published 2020-02-04. Last modified 2026-06-17.