Description


Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions prior to 4.7.0 when an attacker has physical access to an unlocked device, they may enable the integration into the iOS Files app and bypass the Nextcloud pin/password protection and gain access to a users files. It is recommended that the Nextcloud iOS app is upgraded to 4.7.0. There are no known workarounds for this vulnerability.

Related CPE's


Weaknesses



CWE-281CWE-287


NVD-CWE-noinfo

CVSS impact metrics


CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L

4.4 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-03-30T17:15:06.837Z

2 years ago

Last modified

2024-11-21T06:55:44.097Z

1 year ago