openSUSE-SU-2021:0577-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0577-1
openSUSE-SU-2021:0577-1
Summary: Security update for nextcloud-desktop
Details: This update for nextcloud-desktop fixes the following issues: nextcloud-desktop was updated to 3.1.3: - desktop#2884 [stable-3.1] Add support for Hirsute - desktop#2920 [stable-3.1] Validate sensitive URLs to onle allow http(s) schemes. - desktop#2926 [stable-3.1] Validate the providers ssl certificate - desktop#2939 Bump release to 3.1.3 This also fix security issues: - (boo#1184770, CVE-2021-22879, NC-SA-2021-008 , CWE-99) Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/YL7MF53UDFP75PXEIEPNXBAJQBN6ZIBB/, https://bugzilla.suse.com/1184770, https://www.suse.com/security/cve/CVE-2021-22879
Affected packages
Package
Name: nextcloud-desktop
Purl: pkg:rpm/opensuse/nextcloud-desktop&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
