CVE-2021-32658: Sensitive data may not be removed from storage on account removal
Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Android client may not properly clean all sensitive data on account removal. This could include sensitive key material such as the End-to-End encryption keys. It is recommended that the Nextcloud Android App is upgraded to 3.16.1
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-32658?
CVE-2021-32658 is a vulnerability in the Nextcloud Android client that could result in sensitive data not being properly removed on account removal.
What is the severity of CVE-2021-32658?
The severity of CVE-2021-32658 is medium.
How does CVE-2021-32658 affect Nextcloud Android?
CVE-2021-32658 affects Nextcloud Android by potentially leaving sensitive data, such as End-to-End encryption keys, on the device after account removal.
How can I fix CVE-2021-32658?
To fix CVE-2021-32658, it is recommended to update the Nextcloud Android client to version 3.16.2 or later.
Where can I find more information about CVE-2021-32658?
More information about CVE-2021-32658 can be found in the references: [GitHub Commit](https://github.com/nextcloud/android/commit/355f3c745b464b741b20a3b96597303490c26333), [Security Advisories](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g5gf-rmhm-wpxw), [HackerOne Report](https://hackerone.com/reports/1189168).