Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-41166

Опубликовано: 26 янв. 2022
Источник: nvd
CVSS3: 4.3
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise required MANAGE_DOCUMENTS permission may view image thumbnails for images it does not have permission to view. Version 3.17.1 contains a patch. There are no known workarounds.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nextcloud:nextcloud:*:*:*:*:*:android:*:*
Версия до 3.17.1 (исключая)

EPSS

Процентиль: 46%
0.0023
Низкий

4.3 Medium

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-276
CWE-276

EPSS

Процентиль: 46%
0.0023
Низкий

4.3 Medium

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-276
CWE-276