SB2019073022 - Input validation error in Nextcloud Server



SB2019073022 - Input validation error in Nextcloud Server

Published: July 30, 2019 Updated: July 17, 2020

Security Bulletin ID SB2019073022
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2019-5451)

The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.

Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.


Remediation

Install update from vendor's website.