Impact
A malicious server administrator can gain full access to an E2EE folder. They can decrypt files, recover the folder structure and add new files.
Patches
It is recommended that the Nextcloud Desktop client is upgraded to 3.6.5
Workarounds
References
Credit
- Martin Albrecht (Royal Holloway, University of London/Kings College London)
- Matilda Backendal (ETH Zurich)
- Daniele Coppola (ETH Zurich)
- Kenneth G. Paterson (ETH Zurich)
For more information
If you have any questions or comments about this advisory:
Impact
A malicious server administrator can gain full access to an E2EE folder. They can decrypt files, recover the folder structure and add new files.
Patches
It is recommended that the Nextcloud Desktop client is upgraded to 3.6.5
Workarounds
References
Credit
For more information
If you have any questions or comments about this advisory: