Insecure digital certificates In nextcloud-desktop
Description
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious server could get the desktop client to encrypt files with a key known to the attacker. This issue is fixed in Nextcloud Desktop 3.7.0. No known workarounds are available.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 3.7.0-1 | ||
debian 11 | - | ||
debian 13 | 3.7.0-1 | ||
debian 14 | 3.7.0-1 |
Aliases
1. 2. 3. 4. 5.