Improper access control in Nextcloud Android App - CVE-2022-29160
Published: May 20, 2022
Vulnerability identifier: #VU63483
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29160
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the information can be misused as sensitive token, images and user related details exist despite of user account being deleted. A local user can gain access to sensitive information on the system
Affected software
Nextcloud Android App
How to mitigate CVE-2022-29160
Install updates from vendor's website.
Nextcloud Android App - update to 3.19.0