Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-52510

Опубликовано: 15 нояб. 2024
Источник: debian
EPSS Низкий

Описание

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nextcloud-desktopfixed3.15.0-1package
nextcloud-desktopignoredbookwormpackage
nextcloud-desktopignoredbullseyepackage

Примечания

  • https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r4qc-m9mj-452v

  • https://github.com/nextcloud/desktop/pull/7333

  • https://github.com/nextcloud/desktop/commit/8cce183ba4ce46ddef58751fe5358efdea8d0114

  • https://github.com/nextcloud/desktop/commit/0e218bc5495abd422490b6b3db35ebc29d751e6c

  • https://github.com/nextcloud/desktop/commit/ef811ff22058d1ec865f8433a6695cb31c9960ab

  • https://github.com/nextcloud/desktop/commit/ddaaf2c344b157aac01312b8d908ffde8e17dc11

EPSS

Процентиль: 53%
0.00301
Низкий

Связанные уязвимости

CVSS3: 4.2
ubuntu
около 1 года назад

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.

CVSS3: 4.2
nvd
около 1 года назад

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.

EPSS

Процентиль: 53%
0.00301
Низкий