Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holder's information. Nextcloud Android version 3.19.0 contains a patch for this issue. There are no known workarounds available.
References
Link | Resource |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xcj9-3jch-qr2r | Issue Tracking Third Party Advisory |
https://github.com/nextcloud/android/pull/9644 | Issue Tracking Patch Third Party Advisory |
https://hackerone.com/reports/1222873 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2022-05-20 09:15
Updated : 2022-06-02 09:26
NVD link : CVE-2022-29160
Mitre link : CVE-2022-29160
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
nextcloud
- nextcloud