SB2022052012 - Improper access control in Nextcloud Android App



SB2022052012 - Improper access control in Nextcloud Android App

Published: May 20, 2022

Security Bulletin ID SB2022052012
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2022-29160)

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the information can be misused as sensitive token, images and user related details exist despite of user account being deleted. A local user can gain access to sensitive information on the system


Remediation

Install update from vendor's website.