SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24886

Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform.

LOW 3.8EPSS 0.38%

Does this matter?

Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.

Description

Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Contacts without applying for the Contacts permission itself. Version 3.19.0 contains a fix for this issue. There are currently no known workarounds.

CVSS 3.1
3.8 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
EPSS
0.38% probability · 32th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-732
Affected
nextcloud/nextcloud
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.