GHSL-2022-059: _GHSL-2022-060: SQL injection vulnerabilities in Owncloud Android app - CVE-2023-24804, CVE-2023-23948
Published Feb 7, 2023
·Updated
The Owncloud Android app uses content providers to manage its data. The provider FileContentProvider has SQL injection vulnerabilities that allow malicious applications or users in the same device to obtain internal information of the app.
Affected Software
1 affected component
ownCloud ownCloud Android
Event History
Feb 7, 2023
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2022-060?
The severity of GHSL-2022-060 is rated as risk 18.
2
How do I fix GHSL-2022-060?
To fix GHSL-2022-060, update the Owncloud Android app to the latest version that addresses the SQL injection vulnerabilities.
3
What vulnerabilities are associated with GHSL-2022-060?
GHSL-2022-060 is associated with SQL injection vulnerabilities identified as CVE-2023-24804 and CVE-2023-23948.
4
What type of vulnerability is GHSL-2022-060?
GHSL-2022-060 is classified as an SQL injection vulnerability.
5
Who is affected by GHSL-2022-060?
Users of the Owncloud Android app are affected by GHSL-2022-060, particularly if they have vulnerable versions installed.