First published: Fri Sep 16 2022(Updated: )
Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud Android app files are not properly protected. As a result access to internal files of the from within the Nextcloud Android app is possible. This may lead to a leak of sensitive information in some cases. It is recommended that the Nextcloud Android app is upgraded to 3.21.0. There are no known workarounds for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud | <3.21.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-39210 is medium with a CVSS score of 5.5.
The affected software of CVE-2022-39210 is Nextcloud Android version up to and excluding 3.21.0.
An attacker can exploit CVE-2022-39210 by gaining access to internal files of the Nextcloud Android app from within the app itself.
The potential impact of CVE-2022-39210 is a leak of sensitive information from the Nextcloud Android app.
Yes, there is a fix available for CVE-2022-39210 in the Nextcloud Android app. Please update to the latest version to address this vulnerability.