You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Desktop client behaves incorrectly if the initial end-to-end-encryption signature is empty
Moderate
nickvergessen
published
GHSA-r4qc-m9mj-452vNov 15, 2024
Package
Desktop
(Nextcloud)
Affected versions
>= 3.0.0
Patched versions
3.14.2
Description
Impact
The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature.
Patches
It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later
Impact
The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature.
Patches
It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later
Workarounds
References
For more information
If you have any questions or comments about this advisory: