Incorrect Access Control in ownCloud Android App by ownCloud
CVE-2022-25339

5.5MEDIUM

Key Information:

Vendor

Owncloud

Status
Vendor
CVE Published:
7 April 2022

What is CVE-2022-25339?

The ownCloud Android app version 2.20 is susceptible to an access control issue, allowing local attackers to manipulate user permissions. This vulnerability can lead to unauthorized access to sensitive user data, highlighting a significant concern for users relying on the app for secure file storage and sharing. It is crucial for users and administrators to stay informed about this vulnerability and adopt any necessary measures to protect their data.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.