CVE Vulnerabilities

CVE-2019-12902

Incomplete Cleanup

Published: Jun 20, 2019 | Modified: Jul 21, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Pydio Cells before 1.5.0 does incomplete cleanup of a users data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted users data.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Cells Pydio * 1.5.0 (excluding)

Potential Mitigations

References