PT-2023-21872 · Nextcloud · Nextcloud Ios

Ctuihu

·

Publicado

2023-03-30

·

Atualizado

2023-04-07

·

CVE-2023-28647

CVSS v3.1

4.4

Média

VetorAV:P/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud iOS versions prior to 4.7.0
Description The issue affects the Nextcloud iOS application, which is used to interface with the Nextcloud home cloud ecosystem. When an attacker has physical access to an unlocked device, they may enable integration into the iOS Files app, bypassing the Nextcloud pin/password protection and gaining access to a user's files.
Recommendations For versions prior to 4.7.0, upgrade the Nextcloud iOS app to 4.7.0 to resolve the issue. At the moment, there is no information about other workarounds for this vulnerability.

Exploit

Correção

Improper Preservation of Permissions

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28647
GHSA-WJGG-2V4P-2GQ6

Produtos afetados

Nextcloud Ios