Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-66549

Опубликовано: 05 дек. 2025
Источник: debian

Описание

Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nextcloud-desktopfixed3.16.6-3package
nextcloud-desktopno-dsabookwormpackage
nextcloud-desktoppostponedbullseyepackage

Примечания

  • https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h9xj-qh76-q3hw

  • https://github.com/nextcloud/desktop/pull/8330

  • Fixed by: https://github.com/nextcloud/desktop/commit/27ede927d4a86939a4243cc6a1fb656ce04512ef (v3.17.0-rc1)

  • Fixed by: https://github.com/nextcloud/desktop/commit/209530ae9a6dd8c6607ef4e33e84393e4ae6e3e3 (v3.16.5)

Связанные уязвимости

CVSS3: 2.4
ubuntu
2 месяца назад

Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.

CVSS3: 2.4
nvd
2 месяца назад

Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.