Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2020-02-04T19:08:57

Updated: 2024-08-05T00:56:20.928Z

Reserved: 2019-08-26T00:00:00

Link: CVE-2019-15611

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-02-04T20:15:11.713

Modified: 2020-02-11T16:59:15.503

Link: CVE-2019-15611

cve-icon Redhat

No data.