CVE-2024-52510
Publication date 15 November 2024
Last updated 30 May 2025
Ubuntu priority
Cvss 3 Severity Score
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
Status
Package | Ubuntu Release | Status |
---|---|---|
nextcloud-desktop | 25.04 plucky |
Needs evaluation
|
24.10 oracular |
Needs evaluation
|
|
24.04 LTS noble |
Needs evaluation
|
|
22.04 LTS jammy |
Needs evaluation
|
|
20.04 LTS focal |
Needs evaluation
|
Severity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Network |
Attack complexity | High |
Privileges required | High |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N |
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2024-52510
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r4qc-m9mj-452v
- https://github.com/nextcloud/desktop/pull/7333
- https://github.com/nextcloud/desktop/commit/8cce183ba4ce46ddef58751fe5358efdea8d0114
- https://github.com/nextcloud/desktop/commit/0e218bc5495abd422490b6b3db35ebc29d751e6c
- https://github.com/nextcloud/desktop/commit/ef811ff22058d1ec865f8433a6695cb31c9960ab
- https://github.com/nextcloud/desktop/commit/ddaaf2c344b157aac01312b8d908ffde8e17dc11
- https://github.com/nextcloud/desktop/commit/97539218e6f63c3a3fd1694cb7d8aef27c5910d7
- https://hackerone.com/reports/2597504