4
CVSSv2

CVE-2021-32728

Published: 18/08/2021 Updated: 04/10/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions before 3.3.0, the Nextcloud Desktop client fails to check if a private key belongs to previously downloaded public certificate. If the Nextcloud instance serves a malicious public key, the data would be encrypted for this key and thus could be accessible to a malicious actor. This issue is fixed in Nextcloud Desktop Client version 3.3.0. There are no known workarounds aside from upgrading.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nextcloud desktop

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Two vulnerabilities were discovered in the Nextcloud desktop client, which could result in information disclosure For the oldstable distribution (buster), these problems have been fixed in version 251-3+deb10u2 For the stable distribution (bullseye), these problems have been fixed in version 311-2+deb11u1 We recommend that you upgrade your n ...