Lack of authenticity of metadata keys allows a malicious server to gain access to E2EE folders
Package
Android
(Nextcloud)
Affected versions
>= 3.13.0
Patched versions
3.25.0
Desktop
(Nextcloud)
>= 3.0.0
3.8.0
iOS
(Nextcloud)
>= 3.0.5
4.8.0
Impact
A malicious server administrator can gain full access to an E2EE folder. They can decrypt files, recover the folder structure and add new files.
Patches
It is recommended that the Nextcloud Desktop client is upgraded to 3.8.0
It is recommended that the Nextcloud Android app is upgraded to 3.25.0
It is recommended that the Nextcloud Android app is upgraded to 4.8.0
Workarounds
References
Credit
For more information
If you have any questions or comments about this advisory: