#VU63483 Improper access control in Nextcloud Android App - CVE-2022-29160

 

#VU63483 Improper access control in Nextcloud Android App - CVE-2022-29160

Published: May 20, 2022


Vulnerability identifier: #VU63483
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-29160
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Nextcloud Android App
Software vendor:
Nextcloud

Description

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the information can be misused as sensitive token, images and user related details exist despite of user account being deleted. A local user can gain access to sensitive information on the system


Remediation

Install updates from vendor's website.

External links