Improper verification of cryptographic signature in desktop - CVE-2023-29000
Published: April 7, 2023 / Updated: April 7, 2023
desktop
Nextcloud
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to desktop client does not verify received signed certificate in the end-to-end encryption. A remote attacker with control over a malicious server can trick the application into encrypting files with a key known to the attacker.