Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NNextcloud
APPNextcloud< 2.24.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Powiązane podatności
CVE-2019-5454CRITICAL9.8PL ✓ten sam produkt
SQL Injection w aplikacji Nextcloud Android — zniszczenie lokalnej pamięci podręcznej
CVE-2021-43863HIGH7.5ten sam produkt
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcl...
CVE-2023-49790MEDIUM4.3ten sam produkt
The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platfor...
CVE-2023-28999MEDIUM6.9ten sam produkt
Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud An...
CVE-2023-28647MEDIUM4.4ten sam produkt
Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions pri...