CVE-2023-29000: Nextcloud Desktop client does not verify received singed certificate in end-to-end encryption
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious server could get the desktop client to encrypt files with a key known to the attacker. This issue is fixed in Nextcloud Desktop 3.7.0. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-29000?
CVE-2023-29000 is a vulnerability in the Nextcloud Desktop Client that allows a malicious server to encrypt files on the client's machine.
How does CVE-2023-29000 affect Nextcloud Desktop Client?
CVE-2023-29000 affects Nextcloud Desktop Client versions 3.0.0 to 3.7.0.
What is the severity of CVE-2023-29000?
CVE-2023-29000 has a severity rating of 6.5 (medium).
How can I mitigate the risk of CVE-2023-29000?
To mitigate the risk of CVE-2023-29000, it is recommended to update Nextcloud Desktop Client to version 3.7.0 or newer.
Where can I find more information about CVE-2023-29000?
You can find more information about CVE-2023-29000 at the following references: [Reference 1](https://github.com/nextcloud/desktop/pull/4949), [Reference 2](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h82x-98q3-7534), [Reference 3](https://hackerone.com/reports/1679267).