A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nextcloud_server | Nextcloud | 13.0.0 (including) | 13.0.11 (excluding) |
Nextcloud_server | Nextcloud | 14.0.0 (including) | 14.0.7 (excluding) |
Nextcloud_server | Nextcloud | 15.0.0 (including) | 15.0.3 (excluding) |
Such a scenario is commonly observed when: