Headline
CVE-2022-25338: ownCloud Android App lock bypass - ownCloud
ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.
Product
Community
Partners
News news* Insights & Updates * ownCloud News
- Forum
- ownCloud Central
- Events
- Upcoming Events
- Social Media
Latest Posts
For the past years we have been working on a new project called "Infinite Scale". For this …
Read more
Manuela Urban (COO, Sovereign Cloud Stack) explains how Sovereign Cloud Stack, federated cloud technology built with Open …
Read more
- Forum
Pricing
Risk: low
CVSS v3 Base Score: 5.3
CVSS v3 Vector: AV:P/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
CWE ID: CWE-284
CWE Name: CWE-284: Improper Access Control
CVE: CVE-2022-25338
Description
An attacker with physical access to the device could bypass the app lock of the ownCloud Android App.
Affected
- ownCloud Android app < 2.20
Action taken
Properly implement the lock screen