CVE-2021-32658
published 2021-06-08CVE-2021-32658: Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Android client may not properly clean all…
PriorityP417medium4.6CVSS 3.1
AVPACLPRNUINSUCHINAN
EPSS
0.30%
22.0th percentile
Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Android client may not properly clean all sensitive data on account removal. This could include sensitive key material such as the End-to-End encryption keys. It is recommended that the Nextcloud Android App is upgraded to 3.16.1
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nextcloud | nextcloud | < 3.16.1 | 3.16.1 |
| nextcloud | security-advisories | < 3.16.1 | 3.16.1 |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/nextcloud/android/commit/355f3c745b464b741b20a3b96597303490c26333https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g5gf-rmhm-wpxwhttps://hackerone.com/reports/1189168https://github.com/nextcloud/android/commit/355f3c745b464b741b20a3b96597303490c26333https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g5gf-rmhm-wpxwhttps://hackerone.com/reports/1189168
2021-06-08
Published