The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise required `MANAGE_DOCUMENTS` permission may view image thumbnails for images it does not have permission to view. Version 3.17.1 contains a patch. There are no known workarounds.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-01-26T22:35:10

Updated: 2022-01-26T22:35:10

Reserved: 2021-09-15T00:00:00


Link: CVE-2021-41166

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-26T23:15:08.217

Modified: 2022-02-02T19:29:16.787


Link: CVE-2021-41166

JSON object: View

cve-icon Redhat Information

No data.

CWE