CVE Vulnerabilities

CVE-2019-5453

Improper Authentication

Published: Jul 30, 2019 | Modified: Dec 18, 2020
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Nextcloud Nextcloud * 3.2.4 (including)
Nextcloud Nextcloud 3.3.0-rc1 (including) 3.3.0-rc1 (including)
Nextcloud Nextcloud 3.3.0-rc2 (including) 3.3.0-rc2 (including)
Nextcloud Nextcloud 3.3.0-rc3 (including) 3.3.0-rc3 (including)

Potential Mitigations

References