Thumbnails of files leaked via Android content provider (NC-SA-2019-007)
26th July 2019
Risk level: Low
CVSS v3 Base Score: 4.3 (AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N)
HackerOne report: 534541
If an attacker has physical access to an Android smartphone without a screen lock, but with nextcloud installed and set up, he can easily access the nextcloud-files even if the nextcloud app is locked with a fingerprint or pin.
- Nextcloud Android < 3.6.2 (CVE-2019-5452)
The error has been fixed.
It is recommended that users upgrade to version 3.6.2.
The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:
This advisory is licensed CC BY-SA 4.0.