CVE Vulnerabilities

CVE-2019-12902

Incomplete Cleanup

Published: Jun 20, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Pydio Cells before 1.5.0 does incomplete cleanup of a users data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted users data.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Cells Pydio * 1.5.0 (excluding)

Potential Mitigations

References