Vulnerability Description
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Nextcloud | <= 3.2.4 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/331489ExploitThird Party Advisory
- https://hackerone.com/reports/331489ExploitThird Party Advisory
FAQ
What is CVE-2019-5453?
CVE-2019-5453 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
How severe is CVE-2019-5453?
CVE-2019-5453 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5453?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Nextcloud.