CVE-2024-52510
published 2024-11-15CVE-2024-52510: The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.73%
50.1th percentile
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nextcloud-desktop | < nextcloud-desktop 3.15.0-1 (forky) | nextcloud-desktop 3.15.0-1 (forky) |
| nextcloud | desktop | >= 3.0.0 < 3.14.2 | 3.14.2 |
| nextcloud | security-advisories | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-52510: nextcloud-desktop - The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Serve...
vendor_debian·2024·CVSS 4.2
CVE-2024-52510 [MEDIUM] CVE-2024-52510: nextcloud-desktop - The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Serve...
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.15.0-1)
sid: resolved (fixed in 3.15.0-1)
trixie: resolved (fixed in 3.15.0-1)
OSV
CVE-2024-52510: The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer
osv·2024-11-15·CVSS 7.5
CVE-2024-52510 [HIGH] CVE-2024-52510: The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-15
Published