CVE-2021-41256

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-41256
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-41256.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-41256
Related
  • GHSA-2q9v-q3cc-h9f3
Published
2021-11-30T21:15:08Z
Modified
2025-07-01T12:53:58.285007Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicious application installed on the same device can send it an arbitrary Intent that gets reflected back, unintentionally giving read and write access to non-exported Content Providers in Nextcloud News for Android. Users should upgrade to version 0.9.9.63 or higher as soon as possible.

References

Affected packages

Git / github.com/nextcloud/news-android

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/news-android
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.4.10
0.5.2
0.9.9.19
0.9.9.19.1
0.9.9.19.2

v.*

v.0.7.4
v.0.7.5
v.0.7.7
v.0.8.4
v.0.8.4.5
v.0.8.8
v.0.8.9.5
v.0.9.0
v.0.9.1
v.0.9.3
v.0.9.4
v.0.9.5
v.0.9.5.2
v.0.9.6.1
v.0.9.6.3
v.0.9.7
v.0.9.7.2
v.0.9.7.3
v.0.9.7.4
v.0.9.7.5
v.0.9.7.6
v.0.9.8
v.0.9.8.1
v.0.9.8.2
v.0.9.8.3
v.0.9.8.3.1
v.0.9.8.4
v.0.9.8.5
v.0.9.8.7
v.0.9.9.0
v.0.9.9.1
v.0.9.9.10
v.0.9.9.11
v.0.9.9.11-1
v.0.9.9.12
v.0.9.9.13
v.0.9.9.15
v.0.9.9.16
v.0.9.9.16.1
v.0.9.9.17.1
v.0.9.9.18
v.0.9.9.19.2
v.0.9.9.2
v.0.9.9.20
v.0.9.9.21
v.0.9.9.22
v.0.9.9.23
v.0.9.9.24
v.0.9.9.25
v.0.9.9.26
v.0.9.9.3
v.0.9.9.31
v.0.9.9.32
v.0.9.9.33
v.0.9.9.34
v.0.9.9.35
v.0.9.9.36
v.0.9.9.38
v.0.9.9.4
v.0.9.9.40
v.0.9.9.50
v.0.9.9.6
v.0.9.9.60
v.0.9.9.61
v.0.9.9.62
v.0.9.9.7
v.0.9.9.8
v.0.9.9.9
v.0.9.9.9.1

v0.*

v0.5.4
v0.5.5
v0.5.8
v0.6.1
v0.6.9.5
v0.9.9.35