PT-2021-6528 · Nextcloud+1 · Nextcloud Desktop Client+1
Rtod
·
Published
2021-08-18
·
Updated
2023-08-30
·
CVE-2021-32728
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Desktop Client versions prior to 3.3.0
Description
The issue is related to the end-to-end encryption feature of the Nextcloud Desktop Client, where the client fails to check if a private key belongs to a previously downloaded public certificate. This allows a remote attacker to potentially access confidential data if the Nextcloud instance serves a malicious public key. The data would be encrypted for this key, making it accessible to a malicious actor.
Recommendations
For versions prior to 3.3.0, upgrade to Nextcloud Desktop Client version 3.3.0 to fix the issue. As a temporary workaround, consider restricting access to the API endpoint used for downloading public and private keys until the upgrade is possible. Avoid using the end-to-end encryption feature with untrusted Nextcloud instances to minimize the risk of exploitation.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Nextcloud Desktop Client