Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Android client may not properly clean all sensitive data on account removal. This could include sensitive key material such as the End-to-End encryption keys. It is recommended that the Nextcloud Android App is upgraded to 3.16.1
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
Link | Tags |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g5gf-rmhm-wpxw | third party advisory |
https://github.com/nextcloud/android/commit/355f3c745b464b741b20a3b96597303490c26333 | third party advisory patch |
https://hackerone.com/reports/1189168 | exploit third party advisory patch |