Vulnerability Description
Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Nextcloud | < 3.6.2 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/534541ExploitThird Party Advisory
- https://hackerone.com/reports/534541ExploitThird Party Advisory
FAQ
What is CVE-2019-5452?
CVE-2019-5452 is a vulnerability with a CVSS score of 2.4 (LOW). Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved.
How severe is CVE-2019-5452?
CVE-2019-5452 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5452?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Nextcloud.