PT-2022-16955 · Nextcloud · Nextcloud Android App

Dashingjaved

·

Published

2022-04-27

·

Updated

2022-05-06

·

CVE-2022-24885

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Android app versions prior to 3.19.1
Description The issue allows users to bypass a lock on the Nextcloud app on an Android device by repeatedly reopening the app. This is a problem related to the Android client for Nextcloud, a self-hosted productivity platform.
Recommendations For versions prior to 3.19.1, update to version 3.19.1 to resolve the issue. As a temporary workaround, consider restricting access to the app to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24885
GHSA-32J4-9XF3-H2MG

Affected Products

Nextcloud Android App