CVE Vulnerabilities

CVE-2019-12902

Incomplete Cleanup

Published: Jun 20, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Pydio Cells before 1.5.0 does incomplete cleanup of a users data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted users data.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

NameVendorStart VersionEnd Version
CellsPydio*1.5.0 (excluding)

Potential Mitigations

References