7.1

CVE-2021-41256

Exploit

Intent URI permissions manipulation in nextcloud news-android

nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicious application installed on the same device can send it an arbitrary Intent that gets reflected back, unintentionally giving read and write access to non-exported Content Providers in Nextcloud News for Android. Users should upgrade to version 0.9.9.63 or higher as soon as possible.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextcloud ≫ News SwPlatform android Version < 0.9.9.63
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.08% 0.606
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
security-advisories@github.com 5.8 0.6 5.2
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

https://github.com/nextcloud/news-android/blob/master/security/GHSL-2021-1033_Nextcloud_News_for_Android.md
Third Party Advisory
Exploit
https://github.com/nextcloud/news-android/commit/05449cb666059af7de2302df9d5c02997a23df85
Patch
Third Party Advisory
https://github.com/nextcloud/news-android/security/advisories/GHSA-2q9v-q3cc-h9f3
Patch
Third Party Advisory