CVE-2024-52510
Publication date 15 November 2024
Last updated 20 November 2024
Ubuntu priority
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
Status
Package | Ubuntu Release | Status |
---|---|---|
nextcloud-desktop | 24.10 oracular |
Needs evaluation
|
24.04 LTS noble |
Needs evaluation
|
|
22.04 LTS jammy |
Needs evaluation
|
|
20.04 LTS focal |
Needs evaluation
|
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2024-52510
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r4qc-m9mj-452v
- https://github.com/nextcloud/desktop/pull/7333
- https://github.com/nextcloud/desktop/commit/8cce183ba4ce46ddef58751fe5358efdea8d0114
- https://github.com/nextcloud/desktop/commit/0e218bc5495abd422490b6b3db35ebc29d751e6c
- https://github.com/nextcloud/desktop/commit/ef811ff22058d1ec865f8433a6695cb31c9960ab
- https://github.com/nextcloud/desktop/commit/ddaaf2c344b157aac01312b8d908ffde8e17dc11
- https://github.com/nextcloud/desktop/commit/97539218e6f63c3a3fd1694cb7d8aef27c5910d7
- https://hackerone.com/reports/2597504