First published: Tue Jun 08 2021(Updated: )
Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Android client may not properly clean all sensitive data on account removal. This could include sensitive key material such as the End-to-End encryption keys. It is recommended that the Nextcloud Android App is upgraded to 3.16.1
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud | <3.16.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32658 is a vulnerability in the Nextcloud Android client that could result in sensitive data not being properly removed on account removal.
The severity of CVE-2021-32658 is medium.
CVE-2021-32658 affects Nextcloud Android by potentially leaving sensitive data, such as End-to-End encryption keys, on the device after account removal.
To fix CVE-2021-32658, it is recommended to update the Nextcloud Android client to version 3.16.2 or later.
More information about CVE-2021-32658 can be found in the references: [GitHub Commit](https://github.com/nextcloud/android/commit/355f3c745b464b741b20a3b96597303490c26333), [Security Advisories](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g5gf-rmhm-wpxw), [HackerOne Report](https://hackerone.com/reports/1189168).