CVE-2023-28999
published 2023-04-04CVE-2023-28999: Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS…
PriorityP431medium6.4CVSS 3.1
AVNACLPRHUIRSUCHIHAL
EPSS
0.68%
48.5th percentile
Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder structure and add new files. This issue is fixed in Nextcloud Desktop 3.8.0, Nextcloud Android 3.25.0, and Nextcloud iOS 4.8.0. No known workarounds are available.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nextcloud-desktop | < nextcloud-desktop 3.9.0-1 (forky) | nextcloud-desktop 3.9.0-1 (forky) |
| nextcloud | desktop | >= 3.0.0 < 3.8.0 | 3.8.0 |
| nextcloud | nextcloud | >= 3.0.5 < 4.8.0 | 4.8.0 |
| nextcloud | nextcloud | >= 3.13.0 < 3.25.0 | 3.25.0 |
| nextcloud | security-advisories | — | — |
| nextcloud | security-advisories | — | — |
| nextcloud | security-advisories | — | — |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
osv6.4MEDIUM
vendor_debian6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-28999: Nextcloud is an open-source productivity platform
osv·2023-04-04·CVSS 6.4
CVE-2023-28999 [MEDIUM] CVE-2023-28999: Nextcloud is an open-source productivity platform
Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder structure and add new files. This issue is fixed in Nextcloud Desktop 3.8.0, Nextcloud Android 3.25.0, and Nextcloud iOS 4.8.0. No known workarounds are available.
Debian
CVE-2023-28999: nextcloud-desktop - Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3...
vendor_debian·2023·CVSS 6.9
CVE-2023-28999 [MEDIUM] CVE-2023-28999: nextcloud-desktop - Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3...
Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder structure and add new files. This issue is fixed in Nextcloud Desktop 3.8.0, Nextcloud Android 3.25.0, and Nextcloud iOS 4.8.0. No known workarounds are available.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.9.0-1)
sid: resolved (fixed in 3.9.0-1)
trixie: resolved (fixed in 3.9.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://ethz.ch/content/dam/ethz/special-interest/infk/inst-infsec/appliedcrypto/education/theses/report_DanieleCoppola.pdfhttps://github.com/nextcloud/desktop/pull/5560https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8875-wxww-3rr8https://ethz.ch/content/dam/ethz/special-interest/infk/inst-infsec/appliedcrypto/education/theses/report_DanieleCoppola.pdfhttps://github.com/nextcloud/desktop/pull/5560https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8875-wxww-3rr8
2023-04-04
Published