VulnerabilityModified
CVE-2023-35173
By providing an invalid meta data file, an attacker can make previously dropped files inaccessible.
MEDIUM 6.5EPSS 0.49%
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4 that contains the fix.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- nextcloud/end-to-end encryption
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/end_to_end_encryption/pull/435Patch
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x7c7-v5r3-mg37Vendor Advisory
- https://hackerone.com/reports/1914115Third Party Advisory
- https://github.com/nextcloud/end_to_end_encryption/pull/435Patch
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x7c7-v5r3-mg37Vendor Advisory
- https://hackerone.com/reports/1914115Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.