PT-2023-21872 · Nextcloud · Nextcloud Ios
Ctuihu
·
Publicado
2023-03-30
·
Atualizado
2023-04-07
·
CVE-2023-28647
CVSS v3.1
4.4
Média
| Vetor | AV:P/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Nextcloud iOS versions prior to 4.7.0
Description
The issue affects the Nextcloud iOS application, which is used to interface with the Nextcloud home cloud ecosystem. When an attacker has physical access to an unlocked device, they may enable integration into the iOS Files app, bypassing the Nextcloud pin/password protection and gaining access to a user's files.
Recommendations
For versions prior to 4.7.0, upgrade the Nextcloud iOS app to 4.7.0 to resolve the issue.
At the moment, there is no information about other workarounds for this vulnerability.
Exploit
Correção
Improper Preservation of Permissions
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Nextcloud Ios