CVE-2023-35173
CVE-2023-35173 is a medium-severity vulnerability in Nextcloud End-to-end Encryption with a CVSS 3.x base score of 5.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-284.
Key facts
- Severity: Medium (CVSS 3.x base score 5.7)
- EPSS exploit prediction: 0% (41st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-284
- Affected product: Nextcloud End-to-end Encryption
- Published:
- Last modified:
Description
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4 that contains the fix.
Frequently asked questions
- What is CVE-2023-35173?
- Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4 that contains the fix.
- How severe is CVE-2023-35173?
- CVE-2023-35173 has a CVSS 3.x base score of 5.7, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2023-35173 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (41st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-35173?
- CVE-2023-35173 affects Nextcloud End-to-end Encryption. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-35173?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-35173 published?
- CVE-2023-35173 was published on 2023-06-23 and last updated on 2026-06-17.
References
- https://github.com/nextcloud/end_to_end_encryption/pull/435
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x7c7-v5r3-mg37
- https://hackerone.com/reports/1914115
Affected products (1)
- cpe:2.3:a:nextcloud:end-to-end_encryption:*:*:*:*:*:*:*:*
More vulnerabilities in Nextcloud End-to-end Encryption
- CVE-2021-22906 — Medium (CVSS 6.5): Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to…
All CVEs affecting Nextcloud End-to-end Encryption →
Other CWE-284 (Improper Access Control) vulnerabilities
- CVE-2026-83944 — Critical (CVSS 10.0): Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-20192 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine…
- CVE-2026-87230 — Critical (CVSS 10.0): Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The…
- CVE-2026-54745 — Critical (CVSS 10.0): Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0,…
- CVE-2026-18886 — Critical (CVSS 10.0): ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform.…
- CVE-2026-76607 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
Browse all CWE-284 (Improper Access Control) vulnerabilities →