6.5

CVE-2021-22912

Exploit

Default Nextcloud Server and iOS Client leak sharee searches to Nextcloud

Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only on the local Nextcloud server unless a global search has been explicitly chosen by the user.
Mögliche Gegenmaßnahme
Nextcloud iOS Client: None.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudNextcloud SwPlatformiphone_os Version < 3.4.2
Weitere Schwachstelleninformationen
SystemNextcloud App
Produkt Nextcloud iOS Client
Version < 3.4.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.705
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.