Vulnerability Description
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes sensitive data or credentials to a network attacker. This affects the CLI only. It does not affect the standard GUI desktop Nextcloud clients, and it does not affect the Nextcloud server.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Desktop | < 3.6.1 |
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/desktop/issues/4927ExploitIssue TrackingThird Party Advisory
- https://github.com/nextcloud/desktop/pull/5022PatchThird Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-82xx-9Third Party Advisory
- https://hackerone.com/reports/1699740Permissions RequiredThird Party Advisory
- https://github.com/nextcloud/desktop/issues/4927ExploitIssue TrackingThird Party Advisory
- https://github.com/nextcloud/desktop/pull/5022PatchThird Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-82xx-9Third Party Advisory
- https://hackerone.com/reports/1699740Permissions RequiredThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/09/msg00018.html
FAQ
What is CVE-2022-39334?
CVE-2022-39334 is a vulnerability with a CVSS score of 3.9 (LOW). Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS...
How severe is CVE-2022-39334?
CVE-2022-39334 has been rated LOW with a CVSS base score of 3.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-39334?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Desktop.