Untrusted Search Path Affecting nextcloud package, versions [3.0.3,3.3.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NEXTCLOUD-2371414
  • published26 Jan 2022
  • disclosed18 Aug 2021
  • creditUnknown

Introduced: 18 Aug 2021

CVE-2021-37617  (opens in a new tab)
CWE-426  (opens in a new tab)

How to fix?

Upgrade nextcloud to version 3.3.0 or higher.

Overview

Affected versions of this package are vulnerable to Untrusted Search Path. The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3.0.3 through 3.2.4, the Client searches the Uninstall.exe file in a folder that can be written by regular users. This could lead to a case where a malicious user creates a malicious Uninstall.exe, which would be executed with administrative privileges on the Nextcloud Desktop Client installation. This issue is fixed in Nextcloud Desktop Client version 3.3.0. As a workaround, do not allow untrusted users to create content in the C:\ system folder and verify that there is no malicious C:\Uninstall.exe file on the system.

CVSS Scores

version 3.1