Nextcloud · Nextcloud Server · CVE-2019-15612
**Name of the Vulnerable Software and Affected Versions**
Nextcloud Server version 15.0.2
**Description**
A bug in the software causes pending 2FA logins to not be correctly expired when the password of the user is reset.
**Recommendations**
For Nextcloud Server version 15.0.2, update to a newer version that contains a fix for this issue to ensure that pending 2FA logins are correctly expired after a password reset.