CVE-2023-35173: End-to-End encrypted file-drops can be made inaccessible
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4 that contains the fix.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloud End-to-end encryption appto a version that resolves this vulnerability.Fixed in 1.12.4
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35173?
The severity of CVE-2023-35173 is medium with a severity value of 6.5.
How does the Nextcloud End-to-end encryption app vulnerability affect my system?
The vulnerability in the Nextcloud End-to-end encryption app allows an attacker to make previously dropped files inaccessible by providing an invalid metadata file.
Which version of the Nextcloud End-to-end encryption app is affected by CVE-2023-35173?
The version of the Nextcloud End-to-end encryption app affected by CVE-2023-35173 is between 1.12.0 and 1.12.4 (inclusive).
How can I fix CVE-2023-35173?
To fix CVE-2023-35173, it is recommended to upgrade the Nextcloud End-to-end encryption app to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2023-35173?
You can find more information about CVE-2023-35173 in the following references: [GitHub Pull Request](https://github.com/nextcloud/end_to_end_encryption/pull/435), [Nextcloud Security Advisories](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x7c7-v5r3-mg37), [HackerOne Report](https://hackerone.com/reports/1914115).