CVE-2021-22912

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-22912
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22912.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-22912
Related
  • GHSA-m7w4-cvjr-76mh
Published
2021-06-11T16:15:11Z
Modified
2025-07-29T09:31:00.843734Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only on the local Nextcloud server unless a global search has been explicitly chosen by the user.

References

Affected packages

Git / github.com/nextcloud/android

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/android
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/nextcloud/desktop
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/nextcloud/ios
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.12.2
2.17
2.17.1
2.17.2
2.17.3
2.17.4
2.17.5
2.17.6
2.17.7
2.17.8
2.18.0
2.18.1
2.18.2
2.19.0
2.19.1
2.19.2
2.19.3
2.20.0
2.20.1
2.20.2
2.20.3
2.20.4
2.20.5
2.20.6
2.20.7
2.20.8
2.21.0
2.21.1
2.21.2
2.21.3
2.22.0
2.22.1
2.22.2
2.22.3
2.22.4
2.22.5
2.22.6
2.22.7
2.22.8
2.22.9
2.23.0
2.23.1
2.23.2
2.23.3
2.23.4
2.23.5
2.23.6
2.23.7

3.*

3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.1.0
3.2.0
3.3.0
3.4.0
3.4.1

Other

fix-double-navbar
new-design-bug-fix

v2.*

v2.23.8
v2.24.0
v2.24.1
v2.24.2
v2.24.3
v2.24.4
v2.25.0
v2.25.1
v2.25.2
v2.25.3
v2.25.4
v2.25.5
v2.25.6
v2.25.7
v2.25.8
v2.25.9

v3.*

v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8