SB2023040722 - Improper verification of cryptographic signature in Nextcloud Desktop client
Published: April 7, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper verification of cryptographic signature (CVE-ID: CVE-2023-29000)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to desktop client does not verify received signed certificate in the end-to-end encryption. A remote attacker with control over a malicious server can trick the application into encrypting files with a key known to the attacker.
Remediation
Install update from vendor's website.