CVE-2022-24885: Improper Authentication in Nextcloud Android Files
Published Apr 27, 2022
·Updated
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.1, users can bypass a lock on the Nextcloud app on an Android device by repeatedly reopening the app. Version 3.19.1 contains a fix for the problem. There are currently no known workarounds.
Affected Software
1 affected component
Nextcloud Nextcloud android<3.19.1
Remediation
Patch Available
Event History
Apr 27, 2022
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Nextcloud Android app vulnerability?
The vulnerability ID for this Nextcloud Android app vulnerability is CVE-2022-24885.
2
What is the severity level of CVE-2022-24885?
The severity level of CVE-2022-24885 is low.
3
How can an attacker exploit CVE-2022-24885?
An attacker can exploit CVE-2022-24885 by repeatedly reopening the Nextcloud app on an Android device to bypass the lock.
4
What is the affected software of CVE-2022-24885?
The affected software of CVE-2022-24885 is Nextcloud Android app prior to version 3.19.1.
5
How can I fix CVE-2022-24885?
To fix CVE-2022-24885, update your Nextcloud Android app to version 3.19.1 or later.