Headline
CVE-2022-25339: Access to internal files through ownCloud Android App - ownCloud
ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.
Product
Community
Partners
News news* Insights & Updates * ownCloud News
- Forum
- ownCloud Central
- Events
- Upcoming Events
- Social Media
Latest Posts
For the past years we have been working on a new project called "Infinite Scale". For this …
Read more
Manuela Urban (COO, Sovereign Cloud Stack) explains how Sovereign Cloud Stack, federated cloud technology built with Open …
Read more
- Forum
Pricing
Risk: low
CVSS v3 Base Score: 2.8
CVSS v3 Vector: AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CWE ID: CWE-284
CWE Name: CWE-284: Improper Access Control
CVE: CVE-2022-25339
Description
An attacker wich local access to a device with the ownCloud Android app could access internal files of the app.
Affected
- ownCloud Android app < 2.20
Action taken
Fix the access control