CVE-2021-32728

CVSS v3 Score
6.5
Medium
CVSS v2 Score
4.0
Medium

Vulnerability Description

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.3.0, the Nextcloud Desktop client fails to check if a private key belongs to previously downloaded public certificate. If the Nextcloud instance serves a malicious public key, the data would be encrypted for this key and thus could be accessible to a malicious actor. This issue is fixed in Nextcloud Desktop Client version 3.3.0. There are no known workarounds aside from upgrading.

CVSS:6.5(Medium)

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

CVSS:6.5(Medium)

Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.

CVSS:6.5(Medium)

Google Chrome caches TLS sessions before certificate validation occurs.

CVSS:6.5(Medium)

The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certif...

CVSS:6.5(Medium)

In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).

CVSS:6.5(Medium)

curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or fa...