Lucene search

K
hackeroneKaysbugsH1:248656
HistoryJul 12, 2017 - 10:10 a.m.

Nextcloud: bypass of 2FA

2017-07-1210:10:33
kaysbugs
hackerone.com
118

0.001 Low

EPSS

Percentile

44.2%

Improper protection of the 2FA login made a bypass of the 2FA possible.
The bug required to know user credentials but effectively rendered the 2FA ineffective.

The issue has been fixed by the Nextcloud team and has been validated by the reporter.

0.001 Low

EPSS

Percentile

44.2%