Skip to content

Sensitive data may not be removed from storage on account removal

Low
LukasReschke published GHSA-g5gf-rmhm-wpxw Jun 8, 2021

Package

Nextcloud Android Client

Affected versions

< 3.16.1

Patched versions

3.16.1

Description

Impact

Due to a timeout issue the Android client may not properly clean all sensitive data on account removal. This could include sensitive key material such as the End-to-End encryption keys.

Patches

It is recommended that the Nextcloud Android App is upgraded to 3.16.1.

Workarounds

None.

References

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2021-32658

Weaknesses

Credits