CVE-2023-28999Missing Cryptographic Step in Desktop

Severity
6.4MEDIUMNVD
CNA6.9
EPSS
1.1%
top 21.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4

Description

Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder structure and add new files.​ This issue is fixed in Nextcloud Desktop 3.8.0, Nextcloud Android 3.25.0, and Nextcloud iOS 4.8.0. No known workarounds are available.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:LExploitability: 0.9 | Impact: 5.5

Affected Packages3 packages

NVDnextcloud/desktop3.0.03.8.0
NVDnextcloud/nextcloud3.0.54.8.0+1
CVEListV5nextcloud/security-advisories>= 3.0.0, < 3.8.0, >= 3.0.5, < 4.8.0, >= 3.13.0, < 3.25.0+2

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-28999: Nextcloud is an open-source productivity platform2023-04-04
CVEList
Nextcloud: Lack of authenticity of metadata keys allows a malicious server to gain access to E2EE folders2023-04-04

📋Vendor Advisories

1
Debian
CVE-2023-28999: nextcloud-desktop - Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3...2023
CVE-2023-28999 — Missing Cryptographic Step in Desktop | cvebase