CVE-2023-49790: App PIN code can be bypassed in Nextcloud Files iOS
The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platform. Prior to version 4.9.2, the application can be used without providing the 4 digit PIN code. Nextcloud iOS Files app should be upgraded to 4.9.2 to receive the patch. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49790?
CVE-2023-49790 is considered a high severity vulnerability due to the potential for unauthorized access without a PIN code.
How do I fix CVE-2023-49790?
To fix CVE-2023-49790, upgrade the Nextcloud iOS Files app to version 4.9.2 or later.
What does CVE-2023-49790 affect?
CVE-2023-49790 affects the Nextcloud iOS Files app prior to version 4.9.2 on iPhones.
Is there a workaround for CVE-2023-49790?
There is no official workaround for CVE-2023-49790; the only solution is to update to the latest version.
Who is impacted by CVE-2023-49790?
Users of the Nextcloud iOS Files app who haven't updated to version 4.9.2 are impacted by CVE-2023-49790.