First published: Tue Jul 30 2019(Updated: )
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud | =1.0.0 | |
Nextcloud Nextcloud | =1.0.1 | |
Nextcloud Nextcloud | =1.1.0 | |
Nextcloud Nextcloud | =1.1.0-rc1 | |
Nextcloud Nextcloud | =1.1.0-rc2 | |
Nextcloud Nextcloud | =1.2.0 | |
Nextcloud Nextcloud | =1.2.0-rc1 | |
Nextcloud Nextcloud | =1.2.0-rc2 | |
Nextcloud Nextcloud | =1.3.0 | |
Nextcloud Nextcloud | =1.3.0-rc1 | |
Nextcloud Nextcloud | =1.3.0-rc2 | |
Nextcloud Nextcloud | =1.3.1 | |
Nextcloud Nextcloud | =1.4.0 | |
Nextcloud Nextcloud | =1.4.0-rc1 | |
Nextcloud Nextcloud | =1.4.0-rc2 | |
Nextcloud Nextcloud | =1.4.0-rc3 | |
Nextcloud Nextcloud | =1.4.0-rc4 | |
Nextcloud Nextcloud | =1.4.1 | |
Nextcloud Nextcloud | =1.4.1-rc1 | |
Nextcloud Nextcloud | =1.4.1-rc2 | |
Nextcloud Nextcloud | =1.4.1-rc3 | |
Nextcloud Nextcloud | =1.4.1-rc4 | |
Nextcloud Nextcloud | =1.4.2 | |
Nextcloud Nextcloud | =1.4.2-rc1 | |
Nextcloud Nextcloud | =1.4.2-rc2 | |
Nextcloud Nextcloud | =1.4.2-rc3 | |
Nextcloud Nextcloud | =1.4.2-rc4 | |
Nextcloud Nextcloud | =1.4.3 | |
Nextcloud Nextcloud | =2.0.0 | |
Nextcloud Nextcloud | =2.0.0-rc1 | |
Nextcloud Nextcloud | =2.0.0-rc2 | |
Nextcloud Nextcloud | =2.0.0-rc3 | |
Nextcloud Nextcloud | =2.0.0-rc4 | |
Nextcloud Nextcloud | =2.0.0-rc5 | |
Nextcloud Nextcloud | =2.0.0-rc6 | |
Nextcloud Nextcloud | =2.0.0-rc7 | |
Nextcloud Nextcloud | =2.0.0-rc8 | |
Nextcloud Nextcloud | =2.0.0-rc9 | |
Nextcloud Nextcloud | =2.0.1 | |
Nextcloud Nextcloud | =3.0.0-rc1 | |
Nextcloud Nextcloud | =3.0.0-rc2 | |
Nextcloud Nextcloud | =3.0.0-rc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-5454 is critical with a CVSS score of 9.8.
CVE-2019-5454 allows an attacker to execute harmful SQL queries in the Nextcloud Android app, leading to the destruction of a local cache and requiring the user to resetup the account.
Versions 1.0.0 to 3.0.0-rc3 of the Nextcloud Android app are affected by CVE-2019-5454.
To fix CVE-2019-5454, update your Nextcloud Android app to version 3.0.0 or higher.
Yes, you can find additional information about CVE-2019-5454 on the HackerOne report: https://hackerone.com/reports/291764