UBUNTU-CVE-2021-22895
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-22895
Summary:
Details: Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
References: https://ubuntu.com/security/CVE-2021-22895, https://github.com/nextcloud/desktop/pull/2926, https://github.com/nextcloud/desktop/commit/b1ddd0e491b2af0ed040e658d8bcde2a7a61c9fc, https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qpgp-vf4p-wcw5, https://github.com/nextcloud/desktop/releases/tag/v3.1.3, https://hackerone.com/reports/903424, https://www.cve.org/CVERecord?id=CVE-2021-22895
Affected packages
Package
Name: nextcloud-desktop
Purl: pkg:deb/ubuntu/nextcloud-desktop?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
