Bypass lock protection in Android app (NC-SA-2019-008)
26th July 2019
Risk level: Low
CVSS v3 Base Score: 5.9 (AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
HackerOne report: 507172
If an attacker has physical access to an Android smartphone without a screen lock, but with nextcloud installed and set up, they can circumvent the passcode protection by repeatedly opening and closing the app in a very short time.
- Nextcloud Android < 3.6.1 (CVE-2019-5451)
The error has been fixed.
It is recommended that users upgrade to version 3.6.1 or later.
The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:
- Mathijs van Veluw - Vulnerability discovery and disclosure.
This advisory is licensed CC BY-SA 4.0.