PT-2021-6528 · Nextcloud+1 · Nextcloud Desktop Client+1

Rtod

·

Published

2021-08-18

·

Updated

2023-08-30

·

CVE-2021-32728

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Desktop Client versions prior to 3.3.0
Description The issue is related to the end-to-end encryption feature of the Nextcloud Desktop Client, where the client fails to check if a private key belongs to a previously downloaded public certificate. This allows a remote attacker to potentially access confidential data if the Nextcloud instance serves a malicious public key. The data would be encrypted for this key, making it accessible to a malicious actor.
Recommendations For versions prior to 3.3.0, upgrade to Nextcloud Desktop Client version 3.3.0 to fix the issue. As a temporary workaround, consider restricting access to the API endpoint used for downloading public and private keys until the upgrade is possible. Avoid using the end-to-end encryption feature with untrusted Nextcloud instances to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALT-PU-2023-2019
ALT-PU-2023-4584
ALT-PU-2023-5197
BDU:2022-01788
CVE-2021-32728
DSA-4974-1
GHSA-F5FR-5GCV-6CC5
MGASA-2021-0421

Affected Products

Alt Linux
Nextcloud Desktop Client