CVE-2021-22912

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-22912
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22912.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-22912
Related
  • GHSA-m7w4-cvjr-76mh
Published
2021-06-11T16:15:11Z
Modified
2025-01-14T08:52:54.941857Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only on the local Nextcloud server unless a global search has been explicitly chosen by the user.

References

Affected packages

Git / github.com/nextcloud/android

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/android
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/nextcloud/desktop
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/nextcloud/ios
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.12.2
2.17
2.17.1
2.17.2
2.17.3
2.17.4
2.17.5
2.17.6
2.17.7
2.17.8
2.18.0
2.18.1
2.18.2
2.19.0
2.19.1
2.19.2
2.19.3
2.20.0
2.20.1
2.20.2
2.20.3
2.20.4
2.20.5
2.20.6
2.20.7
2.20.8
2.21.0
2.21.1
2.21.2
2.21.3
2.22.0
2.22.1
2.22.2
2.22.3
2.22.4
2.22.5
2.22.6
2.22.7
2.22.8
2.22.9
2.23.0
2.23.1
2.23.2
2.23.3
2.23.4
2.23.5
2.23.6
2.23.7

3.*

3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.1.0
3.2.0
3.3.0
3.4.0
3.4.1

csync-0.*

csync-0.50.0

Other

e2e-tech-preview-1
fix-double-navbar
new-design-bug-fix

v0.*

v0.0.2

v1.*

v1.1.0
v1.1.0-beta1
v1.1.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.3.0
v1.3.0-beta1
v1.3.0-beta2
v1.3.0-beta3
v1.3.0-beta4
v1.4.0
v1.4.0-beta1
v1.4.0-beta2
v1.4.0-rc1
v1.4.1
v1.5.0
v1.5.0-beta1
v1.5.0-beta1-2nd
v1.5.0-beta2
v1.5.0-beta3
v1.5.1
v1.5.1-rc1
v1.5.2
v1.5.3
v1.5.3-rc1
v1.6.0
v1.6.0-beta1
v1.6.0-beta2
v1.6.0-rc1
v1.6.0-rc2
v1.6.0-rc3
v1.6.1
v1.6.1-rc1
v1.6.2
v1.6.2-rc1
v1.6.2-rc2
v1.6.2-themefix
v1.7.0
v1.7.0-alpha1
v1.7.0-beta1
v1.7.0-beta2
v1.7.0-beta3
v1.7.0-beta4
v1.7.0-rc1
v1.7.0beta1
v1.7.0beta2
v1.7.1-beta1
v1.7.1-rc1
v1.8.0
v1.8.0-beta1
v1.8.0-beta1a
v1.8.0-beta2
v1.8.0-rc1
v1.8.0rc1
v1.8.1
v1.8.1-beta1
v1.8.1-rc1
v1.8.1-rc2
v1.8.2
v1.8.2-beta1
v1.8.2-rc1
v1.8.3
v1.8.3-rc1
v1.8.3-rc2
v1.8.3-rc3

v2.*

v2.0.0
v2.0.0-beta2
v2.0.0-rc2
v2.0.1
v2.0.2
v2.0.2-oem
v2.0.2-rc1
v2.0.2-rc2
v2.23.8
v2.24.0
v2.24.1
v2.24.2
v2.24.3
v2.24.4
v2.25.0
v2.25.1
v2.25.2
v2.25.3
v2.25.4
v2.25.5
v2.25.6
v2.25.7
v2.25.8
v2.25.9
v2.5.0
v2.5.0-beta1
v2.5.0-beta2
v2.5.0-rc1
v2.5.0-rc2
v2.5.1
v2.5.2
v2.5.2-rc1
v2.5.3-rc1
v2.5.3-rc2
v2.7.0-beta1
v2.7.0-beta2
v2.7.0-beta3
v2.7.0-rc1

v3.*

v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.1.0
v3.1.0-rc1
v3.1.0-rc2
v3.2.0-rc1
v3.2.0-rc2
v3.2.0-rc3
v3.3.0
v3.3.0-rc1
v3.3.0-rc2
v3.4.0
v3.4.0-do-not-use
v3.4.0-rc1
v3.4.0-rc2
v3.4.1