The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
History

Fri, 15 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 17:45:00 +0000

Type Values Removed Values Added
Description The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
Title Nextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signature is empty
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-15T17:29:44.840Z

Updated: 2024-11-15T18:20:10.869Z

Reserved: 2024-11-11T18:49:23.558Z

Link: CVE-2024-52510

cve-icon Vulnrichment

Updated: 2024-11-15T18:20:04.569Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-15T18:15:29.497

Modified: 2024-11-18T17:11:56.587

Link: CVE-2024-52510

cve-icon Redhat

No data.