Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by default on the lookup server instead of only using the local Nextcloud server unless a global search has been explicitly chosen by the user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2021-06-11T15:49:39
Updated: 2024-08-03T18:58:26.359Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22905
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-06-11T16:15:11.597
Modified: 2024-11-21T05:50:53.157
Link: CVE-2021-22905
Redhat
No data.