CVE-2022-29160: Sensitive files/data exist after deletion of user account in Nextcloud Android
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holder's information. Nextcloud Android version 3.19.0 contains a patch for this issue. There are no known workarounds available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-29160?
CVE-2022-29160 is a vulnerability in Nextcloud Android version prior to 3.19.0 that allows sensitive information to exist after deletion of a user account.
How does CVE-2022-29160 affect Nextcloud Android?
CVE-2022-29160 affects Nextcloud Android versions prior to 3.19.0, where sensitive tokens, images, and user related details can still exist after a user account has been deleted.
What is the severity of CVE-2022-29160?
The severity of CVE-2022-29160 is considered low with a severity value of 3.3.
How can CVE-2022-29160 be exploited?
CVE-2022-29160 can be exploited by an attacker who gains access to a user's deleted account and misuses the sensitive information that still exists.
Is there a fix for CVE-2022-29160?
Yes, the fix for CVE-2022-29160 is to update Nextcloud Android to version 3.19.0 or newer.