Improper access control in ownCloud Android App - CVE-2024-26322

 

Improper access control in ownCloud Android App - CVE-2024-26322

Published: April 25, 2024


Vulnerability identifier: #VU88997
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26322
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a user attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in the Biometric authentication process. An authenticated attacker with physical access can bypass implemented security restrictions and gain unauthorized access to the application.


Affected software

ownCloud Android App

How to mitigate CVE-2024-26322

Install updates from vendor's website.

ownCloud Android App - update to 4.2.0

External References

Related Security Bulletins