BIT-nextcloud-2022-24886
Dashboard / Vulnerabilities / BIT-nextcloud-2022-24886
BIT-nextcloud-2022-24886
Summary: Exposure of Sensitive Information to an Unauthorized Actor in com.nextcloud.client
Details: Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Contacts without applying for the Contacts permission itself. Version 3.19.0 contains a fix for this issue. There are currently no known workarounds.
References: https://github.com/nextcloud/android/pull/9726, https://github.com/nextcloud/security-advisories/security/advisories/GHSA-5cj3-v98r-2wmq, https://hackerone.com/reports/1161401, https://nvd.nist.gov/vuln/detail/CVE-2022-24886
Affected packages
Package
Name: nextcloud
Purl: pkg:bitnami/nextcloud
Affected ranges
Type: SEMVER
Events:
