First published: Thu Jun 17 2021(Updated: )
Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the same device is possible to crash the Nextcloud Android Client due to an uncaught exception. The vulnerability is patched in version 3.15.1.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud | <3.15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32694 is a vulnerability in the Nextcloud Android app that allows a malicious application on the same device to crash the Nextcloud Android Client due to an uncaught exception.
The Nextcloud Android app versions prior to 3.15.1 are affected by CVE-2021-32694.
The severity of CVE-2021-32694 is medium with a CVSS v3.1 score of 5.5.
To fix CVE-2021-32694, update your Nextcloud Android app to version 3.15.1 or later.
Yes, you can find references for CVE-2021-32694 at the following links: [GitHub PR](https://github.com/nextcloud/android/pull/7919), [Nextcloud Security Advisories](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h2gm-m374-99vc), [HackerOne Report](https://hackerone.com/reports/859136).