Vulnerability Description
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Desktop | < 3.1.3 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/desktop/pull/2926PatchThird Party Advisory
- https://github.com/nextcloud/desktop/releases/tag/v3.1.3Release NotesThird Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qpgp-vThird Party Advisory
- https://hackerone.com/reports/903424ExploitIssue TrackingThird Party Advisory
- https://www.debian.org/security/2021/dsa-4974Third Party Advisory
- https://github.com/nextcloud/desktop/pull/2926PatchThird Party Advisory
- https://github.com/nextcloud/desktop/releases/tag/v3.1.3Release NotesThird Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qpgp-vThird Party Advisory
- https://hackerone.com/reports/903424ExploitIssue TrackingThird Party Advisory
- https://www.debian.org/security/2021/dsa-4974Third Party Advisory
FAQ
What is CVE-2021-22895?
CVE-2021-22895 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
How severe is CVE-2021-22895?
CVE-2021-22895 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22895?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Desktop, Debian Debian Linux.