PT-2021-6528 · Nextcloud+1 · Nextcloud Desktop Client+1

·

CVE-2021-32728

·

Published

2021-08-18

·

Updated

2023-08-30

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Desktop Client versions prior to 3.3.0
Description The issue is related to the end-to-end encryption feature of the Nextcloud Desktop Client, where the client fails to check if a private key belongs to a previously downloaded public certificate. This allows a remote attacker to potentially access confidential data if the Nextcloud instance serves a malicious public key. The data would be encrypted for this key, making it accessible to a malicious actor.
Recommendations For versions prior to 3.3.0, upgrade to Nextcloud Desktop Client version 3.3.0 to fix the issue. As a temporary workaround, consider restricting access to the API endpoint used for downloading public and private keys until the upgrade is possible. Avoid using the end-to-end encryption feature with untrusted Nextcloud instances to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-2019
ALT-PU-2023-4584
ALT-PU-2023-5197
BDU:2022-01788
CVE-2021-32728
DSA-4974-1
GHSA-F5FR-5GCV-6CC5
MGASA-2021-0421

Affected Products

Alt Linux
Nextcloud Desktop Client