Bypass Vulnerability in ownCloud for Android App
CVE-2020-36250

4.6MEDIUM

Key Information:

Vendor

Owncloud

Status
Vendor
CVE Published:
19 February 2021

What is CVE-2020-36250?

A flaw exists in the ownCloud application for Android versions prior to 2.15, where the lock protection mechanism can be bypassed by manipulating the system date and time settings. This allows unauthorized access to the application, potentially exposing sensitive user data. Users are advised to update to the latest version to mitigate this risk effectively. For more details, visit ownCloud security advisory.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.