Описание
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Android app uses content providers to manage its data. Prior to version 3.18.1, the providers FileContentProvider and DiskLruImageCacheFileProvider have security issues (an SQL injection, and an insufficient permission control, respectively) that allow malicious apps in the same device to access Nextcloud's data bypassing the permission control system. Users should upgrade to version 3.18.1 to receive a patch. There are no known workarounds aside from upgrading.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- Permissions Required
- PatchThird Party Advisory
- Third Party Advisory
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия до 3.18.1 (исключая)
cpe:2.3:a:nextcloud:nextcloud:*:*:*:*:*:android:*:*
EPSS
Процентиль: 39%
0.00176
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-89
CWE-89
EPSS
Процентиль: 39%
0.00176
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-89
CWE-89