Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-25339: Access to internal files through ownCloud Android App - ownCloud

ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.

CVE
#android

Open-source secure file sync, share and content collaboration with ownCloud

  • Product

  • Community

  • Partners

  • News news* Insights & Updates * ownCloud News

    • Forum
      • ownCloud Central
    • Events
      • Upcoming Events
    • Social Media
      • Facebook
      • Twitter
      • LinkedIn

    Latest Posts

    For the past years we have been working on a new project called "Infinite Scale". For this …

    Read more

    Manuela Urban (COO, Sovereign Cloud Stack) explains how Sovereign Cloud Stack, federated cloud technology built with Open …

    Read more

  • Pricing

  • Risk: low

  • CVSS v3 Base Score: 2.8

  • CVSS v3 Vector: AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

  • CWE ID: CWE-284

  • CWE Name: CWE-284: Improper Access Control

  • CVE: CVE-2022-25339

Description

An attacker wich local access to a device with the ownCloud Android app could access internal files of the app.

Affected

  • ownCloud Android app < 2.20

Action taken

Fix the access control

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda