Thumbnails of files leaked via Android content provider (NC-SA-2019-007)
26th July 2019
Risk level: Low
CVSS v3 Base Score: 4.3 (AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N)
CWE: Improper Access Control (CWE-284)
HackerOne report: 534541
Description
If an attacker has physical access to an Android smartphone without a screen lock, but with nextcloud installed and set up, he can easily access the nextcloud-files even if the nextcloud app is locked with a fingerprint or pin.
Affected Software
- Nextcloud Android < 3.6.2 (CVE-2019-5452)
Action Taken
The error has been fixed.
Resolution
It is recommended that users upgrade to version 3.6.2.
Acknowledgements
The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:
This advisory is licensed CC BY-SA 4.0.