The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.3.0, the Nextcloud Desktop client fails to check if a private key belongs to previously downloaded public certificate. If the Nextcloud instance serves a malicious public key, the data would be encrypted for this key and thus could be accessible to a malicious actor. This issue is fixed in Nextcloud Desktop Client version 3.3.0. There are no known workarounds aside from upgrading.
{
"binaries": [
{
"binary_name": "caja-nextcloud",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "dolphin-nextcloud",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "libnextcloudsync-dev",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "libnextcloudsync0",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nautilus-nextcloud",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nemo-nextcloud",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nextcloud-desktop",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nextcloud-desktop-cmd",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nextcloud-desktop-common",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nextcloud-desktop-l10n",
"binary_version": "2.6.2-1build1"
}
]
}
{
"binaries": [
{
"binary_name": "caja-nextcloud",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "dolphin-nextcloud",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "libnextcloudsync-dev",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "libnextcloudsync0",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nautilus-nextcloud",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nemo-nextcloud",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nextcloud-desktop",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nextcloud-desktop-cmd",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nextcloud-desktop-common",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nextcloud-desktop-l10n",
"binary_version": "3.4.2-1ubuntu1"
}
]
}