CVE-2024-52510
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
15/11/2024
Last modified:
28/08/2025
Description
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
Impact
Base Score 3.x
4.20
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nextcloud:desktop:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.14.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



