CVE Vulnerabilities

CVE-2022-29160

Incomplete Cleanup

Published: May 20, 2022 | Modified: Jul 21, 2023
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holders information. Nextcloud Android version 3.19.0 contains a patch for this issue. There are no known workarounds available.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Nextcloud Nextcloud * 3.19.0 (excluding)

Potential Mitigations

References