CVE-2022-39210
Access to internal files of the Nextcloud Android app
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.2EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
16 Sep 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud Android app files are not properly protected. As a result access to internal files of the from within the Nextcloud Android app is possible. This may lead to a leak of sensitive information in some cases. It is recommended that the Nextcloud Android app is upgraded to 3.21.0. There are no known workarounds for this issue.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Affected products
nextcloud · security-advisoriesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →