CVE-2022-29160 Information
Jun 07, 2022
cve
Description
Nextcloud Android is the Android client for Nextcloud a self-hosted productivity platform. Prior to version 3.19.0 sensitive tokens images and user related details exist after deletion of a user account. This could result in misuse of the former account holder’s information. Nextcloud Android version 3.19.0 contains a patch for this issue. There are no known workarounds available.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xcj9-3jch-qr2r https://github.com/nextcloud/android/pull/9644 https://hackerone.com/reports/1222873
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
3.3
Share on: