CVE-2021-32695 LOW

CVE-2021-32695: Malicious Android app could access Shared Preferences of the Nextcloud Android client

Vendor Nextcloud
Product security-advisories
Weakness CWE-200 · Info exposure
Published June 17, 2021
Last update August 3, 2024

CVSS base score

3.9/10
Attack vector Physical
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.16.1, a malicious app on the same device could have gotten access to the shared preferences of the Nextcloud Android application. This required user-interaction as a victim had to initiate the sharing flow and choose the malicious app. The shared preferences contain some limited private data such as push tokens and the account name. The vulnerability is patched in version 3.16.1.

Key dates

02Disclosure timeline

June 17, 2021 CVE published
August 3, 2024 Record updated