Skip to main content

Reusing a Nonce, Key Pair in Encryption

CVE-2023-28997

Severity Medium
Score 6.5/10

Summary

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can recover and modify the contents of end-to-end encrypted files. Users should upgrade the Nextcloud Desktop client to 3.6.5 to receive a patch. No known workarounds are available.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • HIGH
  • HIGH
  • NONE

CWE-323 - Reusing a Nonce, Key Pair in Encryption

Nonces should be used for the present occasion and only once.

References

Advisory Timeline

  • Published