Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NNextcloud
APPNextcloud< 2.24.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2019-5454CRITICAL9.8PL ✓same product
SQL Injection w aplikacji Nextcloud Android — zniszczenie lokalnej pamięci podręcznej
CVE-2021-43863HIGH7.5same product
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcl...
CVE-2023-49790MEDIUM4.3same product
The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platfor...
CVE-2023-28999MEDIUM6.9same product
Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud An...
CVE-2023-28647MEDIUM4.4same product
Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions pri...