PT-2021-19836 · Nextcloud · Nextcloud Android App

Rtod

·

Published

2021-06-08

·

Updated

2022-10-25

·

CVE-2021-32658

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Android versions prior to 3.16.1
Description The Nextcloud Android client has a timeout issue that may prevent it from properly cleaning sensitive data when an account is removed. This could include sensitive key material, such as End-to-End encryption keys.
Recommendations For versions prior to 3.16.1, upgrade the Nextcloud Android App to 3.16.1 to resolve the issue.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2021-32658
GHSA-G5GF-RMHM-WPXW

Affected Products

Nextcloud Android App