CVE-2023-35173
MEDIUMNextcloud End-to-end Encryption < 1.12.4 - Improper Access Control
Title source: ruleDescription
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4 that contains the fix.
Scores
CVSS v3
5.7
EPSS
0.0019
EPSS Percentile
40.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-284
Status
published
Affected Products (1)
nextcloud/end-to-end_encryption
< 1.12.4
Timeline
Published
Jun 23, 2023
Tracked Since
Feb 18, 2026