In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.
During file synchronization between the Nextcloud server and the desktop client on Linux, the application incorrectly sets file permission bits. As a result, synchronized files may receive 'world writable' or 'world readable' permissions, i.e., accessible to every user on the operating system — regardless of who they belong to. The bug affects only the Linux client versions in the 3.13.1–3.13.3 range.
A local system user can gain unauthorized read access to other users' synchronized files (violation of confidentiality) or overwrite their contents (violation of integrity). In multi-user environments (servers, shared workstations), consequences may include leakage of sensitive data or its modification.
Nextcloud Desktop Client should be updated to version 3.13.4, in which the issue has been fixed. Additionally, it is recommended to review permissions for synchronized files in the indicated version range and manually correct incorrect permissions (e.g., using the chmod command).
Nextcloud Desktop Client in versions 3.13.1, 3.13.2, and 3.13.3 running on Linux systems.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NLinux Kernel
OSLinuxall versionsNextcloud Desktop
APPNextcloud3.13.1 – 3.13.4 (excl.)
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
RCE przez YAML deserialization w IBM Aspera Faspex
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection
Command Injection w VMware Workspace One Access i Identity Manager