PT-2022-11370 · Nextcloud · Nextcloud Android App
Atorralba
+1
·
Published
2022-01-26
·
Updated
2022-02-02
·
CVE-2021-41166
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Android app versions prior to 3.17.1
Description
The issue may lead to sensitive information disclosure, allowing an unauthorized app without the required
MANAGE DOCUMENTS permission to view image thumbnails for images it does not have permission to view.Recommendations
For versions prior to 3.17.1, update to version 3.17.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive images until the update is applied.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcloud Android App