**minor issue ** -Nextcloud 10.0 session issue with desktop client and android client
Medium
N
Nextcloud
Submitted None
Actions:
Reported by
egrep
Vulnerability Details
Technical details and impact analysis
Scenario:
***********
--> Installed nextcloud 10.0 locally and created "admin" account
--> Installed nextcloud desktop client and andoid client
I found session related vulnerability in nextcloud 10.0 where killing session in User(admin) --> Personal --> Sessions not actually killing sessions in desktop client
Steps:
1) Logged into admin account in browser
2) Logged into admin account in desktop client and android client. Currently admin account is having 3 sessions : browser, desktop, andoid
3) Goto User(admin) --> Personal --> Sessions --> kill desktop client session --> upload new file using browser --> Still dekstop client is syncing files without asking any password prompt (issue1)
4) Though android client is still active, sessions are not capturing in personal --> sessions tab
Hope these are minor issues
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Violation of Secure Design Principles