PT-2022-19421 · Nextcloud · Nextcloud Android App

Geekysherlock

·

Published

2022-05-20

·

Updated

2023-07-21

·

CVE-2022-29160

CVSS v3.1

2.8

Low

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Android versions prior to 3.19.0
Description The issue concerns the existence of sensitive tokens, images, and user-related details after the deletion of a user account in Nextcloud Android. This could lead to the misuse of the former account holder's information.
Recommendations For versions prior to 3.19.0, update to version 3.19.0 to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-29160
GHSA-XCJ9-3JCH-QR2R

Affected Products

Nextcloud Android App