6.1

CVE-2019-5453

Exploit
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextcloud ≫ Nextcloud SwPlatform android Version <= 3.2.4
Nextcloud ≫ Nextcloud Version 3.3.0 Update rc1 SwPlatform android
Nextcloud ≫ Nextcloud Version 3.3.0 Update rc2 SwPlatform android
Nextcloud ≫ Nextcloud Version 3.3.0 Update rc3 SwPlatform android
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.369
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 0.9 5.2
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

https://hackerone.com/reports/331489
Third Party Advisory
Exploit