Improper access control in Nextcloud Android App - CVE-2022-29160

 

Improper access control in Nextcloud Android App - CVE-2022-29160

Published: May 20, 2022


Vulnerability identifier: #VU63483
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29160
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the information can be misused as sensitive token, images and user related details exist despite of user account being deleted. A local user can gain access to sensitive information on the system


Affected software

Nextcloud Android App

How to mitigate CVE-2022-29160

Install updates from vendor's website.

Nextcloud Android App - update to 3.19.0

External References

Related Security Bulletins