Nextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signature is empty
Vulnerability Description
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-52510
Credits & Attribution
No credits recorded in the NVD database.
References
More from nextcloud
View All →Affected Vendor
nextcloud
View all reports →