Lucene search

K
nextcloudNextcloudGHSA-H82X-98Q3-7534
HistoryApr 04, 2023 - 7:53 a.m.

Desktop client does not verify received singed certificate in end-to-end encryption

2023-04-0407:53:30
github.com
21
end-to-end encryption
nextcloud desktop client
certificate verification
malicious server
upgrade
hackerone
pullrequest
security advisory
support ticket

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

38.2%

Description

Impact

By trusting that the server will return a certificate that belongs to the keypair of the user, a malicious server could get the desktop client to encrypt files with a key known to the attacker.

Patches

It is recommended that the Nextcloud Desktop client is upgraded to 3.7.0

Workarounds

  • No workaround available

References

For more information

If you have any questions or comments about this advisory:

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

38.2%