A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://hackerone.com/reports/742588 | third party advisory exploit |
https://nextcloud.com/security/advisory/?id=NC-SA-2020-039 | vendor advisory |
http://seclists.org/fulldisclosure/2020/Dec/55 | third party advisory mailing list |
http://seclists.org/fulldisclosure/2020/Dec/57 | third party advisory mailing list |
http://seclists.org/fulldisclosure/2020/Dec/58 | third party advisory mailing list |