PT-2023-21871 · Nextcloud · Nextcloud Android App

Nickvergessen

·

Published

2023-03-30

·

Updated

2023-04-07

·

CVE-2023-28646

CVSS v3.1

4.4

Medium

VectorAV:P/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud Android versions 3.7.0 through 3.24.0
Description The Nextcloud Android app has a security issue that allows an attacker with access to an unlocked physical device to bypass the Pin/passcode protection using a third-party app. This enables the attacker to view meta information such as sharer, sharees, and activity of files.
Recommendations For versions 3.7.0 through 3.24.0, upgrade the Nextcloud Android app to version 3.24.1 to resolve the issue.

Exploit

Fix

Improper Preservation of Permissions

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-28646
GHSA-C3RF-94H6-VJ8V

Affected Products

Nextcloud Android App