Vulnerability CVE-2023-35173


Published: 2023-06-23

Description:
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4 that contains the fix.

Type:

CWE-284

(Improper Access Control)

 References:
https://hackerone.com/reports/1914115
https://github.com/nextcloud/end_to_end_encryption/pull/435
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x7c7-v5r3-mg37

Copyright 2026, cxsecurity.com

 

Back to Top