CVE-2022-24886: Exposure of Sensitive Information to an Unauthorized Actor in com.nextcloud.client
Published Apr 27, 2022
·Updated
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Contacts without applying for the Contacts permission itself. Version 3.19.0 contains a fix for this issue. There are currently no known workarounds.
Affected Software
1 affected component
Nextcloud Nextcloud android<3.19.0
Event History
Apr 27, 2022
CVE Published
via MITRE·01:30 PM
Data Sourced
via MITRE·01:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-24886?
CVE-2022-24886 is a vulnerability in the Nextcloud Android app that allows any application with notification permission to access contacts without applying for the Contacts permission itself.
2
What is the severity of CVE-2022-24886?
CVE-2022-24886 has a severity rating of 3.8, which is considered low.
3
How can I fix CVE-2022-24886?
To fix CVE-2022-24886, you should update your Nextcloud Android app to version 3.19.0 or later.