{"id":"CVE-2024-52510","summary":"Nextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signature is empty","details":"The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.","aliases":["GHSA-r4qc-m9mj-452v"],"modified":"2026-05-18T05:59:02.530081312Z","published":"2024-11-15T17:29:44.840Z","database_specific":{"cna_assigner":"GitHub_M","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52510.json","cwe_ids":["CWE-295"]},"references":[{"type":"WEB","url":"https://hackerone.com/reports/2597504"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52510.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r4qc-m9mj-452v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52510"},{"type":"FIX","url":"https://github.com/nextcloud/desktop/commit/97539218e6f63c3a3fd1694cb7d8aef27c5910d7"},{"type":"FIX","url":"https://github.com/nextcloud/desktop/pull/7333"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/desktop","events":[{"introduced":"ff175088a391007b66bfca89ef35cf29e37cf001"},{"fixed":"5b9cebb4aba3548101cace9080ea1f98d244d0b3"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-52510.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N"}]}