Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-25338: ownCloud Android App lock bypass - ownCloud

ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.

CVE
#android

Open-source secure file sync, share and content collaboration with ownCloud

  • Product

  • Community

  • Partners

  • News news* Insights & Updates * ownCloud News

    • Forum
      • ownCloud Central
    • Events
      • Upcoming Events
    • Social Media
      • Facebook
      • Twitter
      • LinkedIn

    Latest Posts

    For the past years we have been working on a new project called "Infinite Scale". For this …

    Read more

    Manuela Urban (COO, Sovereign Cloud Stack) explains how Sovereign Cloud Stack, federated cloud technology built with Open …

    Read more

  • Pricing

  • Risk: low

  • CVSS v3 Base Score: 5.3

  • CVSS v3 Vector: AV:P/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

  • CWE ID: CWE-284

  • CWE Name: CWE-284: Improper Access Control

  • CVE: CVE-2022-25338

Description

An attacker with physical access to the device could bypass the app lock of the ownCloud Android App.

Affected

  • ownCloud Android app < 2.20

Action taken

Properly implement the lock screen

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda