BIT-nextcloud-2021-32695

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/nextcloud/BIT-nextcloud-2021-32695.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-nextcloud-2021-32695
Aliases
Published
2026-07-12T23:47:42.345Z
Modified
2026-07-13T06:26:36.607250374Z
Summary
Malicious Android app could access Shared Preferences of the Nextcloud Android client
Details

Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.16.1, a malicious app on the same device could have gotten access to the shared preferences of the Nextcloud Android application. This required user-interaction as a victim had to initiate the sharing flow and choose the malicious app. The shared preferences contain some limited private data such as push tokens and the account name. The vulnerability is patched in version 3.16.1.

Database specific
{
    "severity": "Low",
    "cpes": [
        "cpe:2.3:a:nextcloud:nextcloud:*:*:*:*:*:android:*:*"
    ]
}
References

Affected packages

Bitnami / nextcloud

Package

Name
nextcloud
Purl
pkg:bitnami/nextcloud

Severity

  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.16.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/nextcloud/BIT-nextcloud-2021-32695.json"