Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8236

Опубликовано: 02 нояб. 2020
Источник: nvd
CVSS3: 6.8
CVSS2: 4.6
EPSS Низкий

Описание

A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
Версия до 19.0.2 (исключая)

EPSS

Процентиль: 46%
0.00234
Низкий

6.8 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 6.8
debian
больше 4 лет назад

A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the ...

CVSS3: 6.8
github
около 3 лет назад

A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.

EPSS

Процентиль: 46%
0.00234
Низкий

6.8 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-287
CWE-287