CVE-2019-5454: SQL Injection
Published Jul 30, 2019
·Updated
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.
Affected Software
42 affected components
Nextcloud Nextcloud android=1.0.0
Nextcloud Nextcloud android=1.0.1
Nextcloud Nextcloud android=1.1.0
Nextcloud Nextcloud android=1.1.0-rc1
Nextcloud Nextcloud android=1.1.0-rc2
Nextcloud Nextcloud android=1.2.0
Nextcloud Nextcloud android=1.2.0-rc1
Nextcloud Nextcloud android=1.2.0-rc2
Nextcloud Nextcloud android=1.3.0
Nextcloud Nextcloud android=1.3.0-rc1
Nextcloud Nextcloud android=1.3.0-rc2
Nextcloud Nextcloud android=1.3.1
Nextcloud Nextcloud android=1.4.0
Nextcloud Nextcloud android=1.4.0-rc1
Nextcloud Nextcloud android=1.4.0-rc2
Nextcloud Nextcloud android=1.4.0-rc3
Nextcloud Nextcloud android=1.4.0-rc4
Nextcloud Nextcloud android=1.4.1
Nextcloud Nextcloud android=1.4.1-rc1
Nextcloud Nextcloud android=1.4.1-rc2
Nextcloud Nextcloud android=1.4.1-rc3
Nextcloud Nextcloud android=1.4.1-rc4
Nextcloud Nextcloud android=1.4.2
Nextcloud Nextcloud android=1.4.2-rc1
Nextcloud Nextcloud android=1.4.2-rc2
Nextcloud Nextcloud android=1.4.2-rc3
Nextcloud Nextcloud android=1.4.2-rc4
Nextcloud Nextcloud android=1.4.3
Nextcloud Nextcloud android=2.0.0
Nextcloud Nextcloud android=2.0.0-rc1
Nextcloud Nextcloud android=2.0.0-rc2
Nextcloud Nextcloud android=2.0.0-rc3
Nextcloud Nextcloud android=2.0.0-rc4
Nextcloud Nextcloud android=2.0.0-rc5
Nextcloud Nextcloud android=2.0.0-rc6
Nextcloud Nextcloud android=2.0.0-rc7
Nextcloud Nextcloud android=2.0.0-rc8
Nextcloud Nextcloud android=2.0.0-rc9
Nextcloud Nextcloud android=2.0.1
Nextcloud Nextcloud android=3.0.0-rc1
Nextcloud Nextcloud android=3.0.0-rc2
Nextcloud Nextcloud android=3.0.0-rc3
Remediation
Patch Available
Event History
Jul 30, 2019
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5454?
The severity of CVE-2019-5454 is critical with a CVSS score of 9.8.
2
How does CVE-2019-5454 affect the Nextcloud Android app?
CVE-2019-5454 allows an attacker to execute harmful SQL queries in the Nextcloud Android app, leading to the destruction of a local cache and requiring the user to resetup the account.
3
Which versions of the Nextcloud Android app are affected by CVE-2019-5454?
Versions 1.0.0 to 3.0.0-rc3 of the Nextcloud Android app are affected by CVE-2019-5454.
4
How can I fix the vulnerability in the Nextcloud Android app (CVE-2019-5454)?
To fix CVE-2019-5454, update your Nextcloud Android app to version 3.0.0 or higher.
5
Is there any additional information about CVE-2019-5454?
Yes, you can find additional information about CVE-2019-5454 on the HackerOne report: https://hackerone.com/reports/291764