CVE-2022-39210
Access to internal files of the Nextcloud Android app
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud Android app files are not properly protected. As a result access to internal files of the from within the Nextcloud Android app is possible. This may lead to a leak of sensitive information in some cases. It is recommended that the Nextcloud Android app is upgraded to 3.21.0. There are no known workarounds for this issue.
Nextcloud android es el cliente oficial de Android para la plataforma del servidor doméstico Nextcloud. Las rutas internas de los archivos de la aplicación Nextcloud Android no están protegidas apropiadamente. Como resultado, el acceso a los archivos internos de la desde la aplicación Nextcloud Android es posible. Esto puede conllevar a un filtrado de información confidencial en algunos casos. Es recomendado actualizar la aplicación Nextcloud Android a versión 3.21.0. No se presentan mitigaciones conocidas para este problema
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-02 CVE Reserved
- 2022-09-16 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vw2w-gpcv-v39f | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/nextcloud/android/pull/10544 | 2022-09-21 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Nextcloud Search vendor "Nextcloud" for product "Nextcloud" | < 3.21.0 Search vendor "Nextcloud" for product "Nextcloud" and version " < 3.21.0" | android |
Affected
|