MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2019-15611

CVSS 4.9v3.1pub. 2020-02-04upd. 2024-11-21

Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
  • Nextcloud

    APP
    Nextcloud
    < 2.24.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2019-5454CRITICAL9.8PL ✓same product

SQL Injection w aplikacji Nextcloud Android — zniszczenie lokalnej pamięci podręcznej

CVE-2021-43863HIGH7.5same product

The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcl...

CVE-2023-49790MEDIUM4.3same product

The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platfor...

CVE-2023-28999MEDIUM6.9same product

Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud An...

CVE-2023-28647MEDIUM4.4same product

Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions pri...