PT-2022-11922 · Nextcloud · Nextcloud Android App

Nickvergessen

·

Published

2022-01-25

·

Updated

2022-01-31

·

CVE-2021-43863

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Android app versions prior to 3.18.1
Description The Nextcloud Android app has security issues in its content providers, FileContentProvider and DiskLruImageCacheFileProvider, which include an SQL injection and insufficient permission control. These issues allow malicious apps on the same device to access Nextcloud's data by bypassing the permission control system.
Recommendations For versions prior to 3.18.1, upgrade to version 3.18.1 to receive a patch. As a temporary workaround, consider restricting access to the FileContentProvider and DiskLruImageCacheFileProvider providers until a patch is available.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43863
GHSA-VJP2-F63V-W479

Affected Products

Nextcloud Android App