com.nextcloud.client bypass the protection lock in andoid app v 3.18.1 latest version.

Disclosed: 2022-04-30 11:56:31 By dashingjaved To nextcloud
Low
Vulnerability Details
## Summary: nextcloud allowed multiple account within the android client app on a single lock ## Steps To Reproduce: 1.open nextcloud app 2.add security password to protect the app 3.close the app again open the app and now show the password to open the app 1. so now the password protection bypass lets start 2.hold the nextcloud app and see the app info open it 3.Here the three option 1.open.2.uninstall and 3.force stop now click open button and now see the app lock protection in the app and now open app and back open and back between 3 to 4 time same procedure and now you will see the app lock protection bypass in nextcloud android app ## Supporting Material/References: [list any additional material (e.g. screenshots, logs, etc.)] * [attachment / reference] ## Impact if an attacker has physical access to an android mobile without screen lock,but with nextcloud installed and set up,he can easily access the nextcloud-files. regards:Javed Ahmad
Actions
View on HackerOne
Report Stats
  • Report ID: 1450368
  • State: Closed
  • Substate: resolved
  • Upvotes: 8
Share this report