CVE-2021-32658

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-32658
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32658.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-32658
Related
  • GHSA-g5gf-rmhm-wpxw
Published
2021-06-08T19:15:08Z
Modified
2025-11-15T12:46:18.741553Z
Severity
  • 4.6 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Android client may not properly clean all sensitive data on account removal. This could include sensitive key material such as the End-to-End encryption keys. It is recommended that the Nextcloud Android App is upgraded to 3.16.1

References

Affected packages

Git / github.com/nextcloud/android

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/android
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

vanir_signatures

[
    {
        "deprecated": false,
        "id": "CVE-2021-32658-02da77d0",
        "source": "https://github.com/nextcloud/android/commit/355f3c745b464b741b20a3b96597303490c26333",
        "signature_version": "v1",
        "target": {
            "function": "onShow",
            "file": "src/main/java/com/owncloud/android/ui/dialog/SetupEncryptionDialogFragment.java"
        },
        "signature_type": "Function",
        "digest": {
            "function_hash": "204074037388779280763450898895248817851",
            "length": 2358.0
        }
    },
    {
        "deprecated": false,
        "id": "CVE-2021-32658-0803d86c",
        "source": "https://github.com/nextcloud/android/commit/355f3c745b464b741b20a3b96597303490c26333",
        "signature_version": "v1",
        "target": {
            "file": "src/androidTest/java/com/owncloud/android/util/EncryptionTestIT.java"
        },
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "187228872876105348036970258530191140453",
                "334574834211272699017174966348165351805",
                "265633840322947791086459243648463926270",
                "194393095113473704750056911003475155917",
                "318227661396509153018103162566783730728",
                "276242121823470279180546149186572731266"
            ]
        }
    },
    {
        "deprecated": false,
        "id": "CVE-2021-32658-9a14ab98",
        "source": "https://github.com/nextcloud/android/commit/355f3c745b464b741b20a3b96597303490c26333",
        "signature_version": "v1",
        "target": {
            "file": "src/main/java/com/owncloud/android/ui/dialog/SetupEncryptionDialogFragment.java"
        },
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "244354890822681210340708690372476696216",
                "276175414959636470934100714440262568006",
                "270400207281040229207731533172221799571",
                "283016320702720658321535024877125321253",
                "252182610927001997982342675021192789854",
                "49990051135529676913333977221101261234",
                "35846233045639326006550518321390833185",
                "99370553752790220633521166182452143193",
                "19760939333898780074823811886881491450",
                "326044477257720045345069399434529145025",
                "144832760916861151637757728659479166444",
                "159134019731081907958418847340629525614",
                "65903818700669486635972947098166822889",
                "152421207822351688710006219832677963396",
                "318592074659712864545570398672427433054",
                "19655283731221524543373420016834426384",
                "128450659928022079911455104276321034394",
                "14047099173889929277980255550449628321",
                "152819290237229156072148499944965142571",
                "314044462896887897040338554867502794985",
                "238427648856996349705978235619622898175",
                "131294009652155117594029678758280393229",
                "259639771153797408274850902463573606721",
                "117894929845208657074642191412142851666",
                "69603510908865639998773868169712859513",
                "221953092495114475234925221949452369963",
                "179136598032103585096285304193398107359",
                "335766460096705856275229625178856732949"
            ]
        }
    },
    {
        "deprecated": false,
        "id": "CVE-2021-32658-f239a1b5",
        "source": "https://github.com/nextcloud/android/commit/355f3c745b464b741b20a3b96597303490c26333",
        "signature_version": "v1",
        "target": {
            "function": "onClick",
            "file": "src/main/java/com/owncloud/android/ui/dialog/SetupEncryptionDialogFragment.java"
        },
        "signature_type": "Function",
        "digest": {
            "function_hash": "250343245634420227883648114532362506038",
            "length": 1858.0
        }
    },
    {
        "deprecated": false,
        "id": "CVE-2021-32658-f9377250",
        "source": "https://github.com/nextcloud/android/commit/355f3c745b464b741b20a3b96597303490c26333",
        "signature_version": "v1",
        "target": {
            "function": "createDialog",
            "file": "src/main/java/com/owncloud/android/ui/dialog/SetupEncryptionDialogFragment.java"
        },
        "signature_type": "Function",
        "digest": {
            "function_hash": "281354828577392710637449536751707036637",
            "length": 2799.0
        }
    }
]

Git / github.com/nextcloud/desktop

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/desktop
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

csync-0.*

csync-0.50.0

Other

e2e-tech-preview-1

v0.*

v0.0.2

v1.*

v1.1.0
v1.1.0-beta1
v1.1.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.3.0
v1.3.0-beta1
v1.3.0-beta2
v1.3.0-beta3
v1.3.0-beta4
v1.4.0
v1.4.0-beta1
v1.4.0-beta2
v1.4.0-rc1
v1.4.1
v1.5.0
v1.5.0-beta1
v1.5.0-beta1-2nd
v1.5.0-beta2
v1.5.0-beta3
v1.5.1
v1.5.1-rc1
v1.5.2
v1.5.3
v1.5.3-rc1
v1.6.0
v1.6.0-beta1
v1.6.0-beta2
v1.6.0-rc1
v1.6.0-rc2
v1.6.0-rc3
v1.6.1
v1.6.1-rc1
v1.6.2
v1.6.2-rc1
v1.6.2-rc2
v1.6.2-themefix
v1.7.0
v1.7.0-alpha1
v1.7.0-beta1
v1.7.0-beta2
v1.7.0-beta3
v1.7.0-beta4
v1.7.0-rc1
v1.7.0beta1
v1.7.0beta2
v1.7.1-beta1
v1.7.1-rc1
v1.8.0
v1.8.0-beta1
v1.8.0-beta1a
v1.8.0-beta2
v1.8.0-rc1
v1.8.0rc1
v1.8.1
v1.8.1-beta1
v1.8.1-rc1
v1.8.1-rc2
v1.8.2
v1.8.2-beta1
v1.8.2-rc1
v1.8.3
v1.8.3-rc1
v1.8.3-rc2
v1.8.3-rc3

v2.*

v2.0.0
v2.0.0-beta2
v2.0.0-rc2
v2.0.1
v2.0.2
v2.0.2-oem
v2.0.2-rc1
v2.0.2-rc2
v2.5.0
v2.5.0-beta1
v2.5.0-beta2
v2.5.0-rc1
v2.5.0-rc2
v2.5.1
v2.5.2
v2.5.2-rc1
v2.5.3-rc1
v2.5.3-rc2
v2.7.0-beta1
v2.7.0-beta2
v2.7.0-beta3
v2.7.0-rc1

v3.*

v3.1.0
v3.1.0-rc1
v3.1.0-rc2
v3.16.0
v3.16.0-rc1
v3.16.0-rc2
v3.16.0-rc3
v3.16.0-rc4
v3.2.0-rc1
v3.2.0-rc2
v3.2.0-rc3
v3.3.0
v3.3.0-rc1
v3.3.0-rc2
v3.4.0-do-not-use
v3.4.0-rc1
v3.4.0-rc2
v3.5.0
v3.5.0-rc1
v3.5.0-rc2
v3.5.0-rc3
v3.5.0-rc4
v3.6.0
v3.6.0-rc1
v3.6.0-rc2