CVE-2021-41166Incorrect Default Permissions in Security-advisories

Severity
5.3MEDIUMNVD
CNA4.3
EPSS
0.2%
top 54.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26

Description

The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise required `MANAGE_DOCUMENTS` permission may view image thumbnails for images it does not have permission to view. Version 3.17.1 contains a patch. There are no known workarounds.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDnextcloud/nextcloud< 3.17.1
CVEListV5nextcloud/security-advisories< 3.17.1

Patches

🔴Vulnerability Details

1
CVEList
Permission bypass in Nextcloud Android App2022-01-26
CVE-2021-41166 — Incorrect Default Permissions | cvebase