CVE-2021-43863 Information
Description
The Nextcloud Android app is the Android client for Nextcloud a self-hosted productivity platform. The Nextcloud Android app uses content providers to manage its data. Prior to version 3.18.1 the providers FileContentProvider and DiskLruImageCacheFileProvider have security issues (an SQL injection and an insufficient permission control respectively) that allow malicious apps in the same device to access Nextcloud’s data bypassing the permission control system. Users should upgrade to version 3.18.1 to receive a patch. There are no known workarounds aside from upgrading.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://github.com/nextcloud/android/security/advisories/GHSA-vjp2-f63v-w479 https://hackerone.com/reports/1358597 https://github.com/nextcloud/android/commit/627caba60e69e223b0fc89c4cb18eaa76a95db95
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: