CVE-2021-22895 — Improper Certificate Validation in Desktop
Severity
5.9MEDIUMNVD
EPSS
0.4%
top 41.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Description
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2021-22895: nextcloud-desktop - Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate vali...↗2021