PT-2021-19836 · Nextcloud · Nextcloud Android App
Rtod
·
Published
2021-06-08
·
Updated
2022-10-25
·
CVE-2021-32658
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Android versions prior to 3.16.1
Description
The Nextcloud Android client has a timeout issue that may prevent it from properly cleaning sensitive data when an account is removed. This could include sensitive key material, such as End-to-End encryption keys.
Recommendations
For versions prior to 3.16.1, upgrade the Nextcloud Android App to 3.16.1 to resolve the issue.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Android App