CVE-2021-22905
Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by default on the lookup server instead of only using the local Nextcloud server unless a global search has…
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by default on the lookup server instead of only using the local Nextcloud server unless a global search has been explicitly chosen by the user.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- nextcloud/nextcloud
- Source
- support@hackerone.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-22v9-q3r6-x7cjThird Party Advisory
- https://hackerone.com/reports/1167916Exploit, Issue Tracking, Third Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-22v9-q3r6-x7cjThird Party Advisory
- https://hackerone.com/reports/1167916Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.