6.5

CVE-2021-22905

Exploit

Default Nextcloud Server and Android Client leak sharee searches to Nextcloud

Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by default on the lookup server instead of only using the local Nextcloud server unless a global search has been explicitly chosen by the user.
Mögliche Gegenmaßnahme
Nextcloud Android Client: None.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudNextcloud SwPlatformandroid Version < 3.16.0
Weitere Schwachstelleninformationen
SystemNextcloud App
Produkt Nextcloud Android Client
Version < 3.16.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.708
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.