CVE-2021-22895Improper Certificate Validation in Desktop

Severity
5.9MEDIUMNVD
EPSS
0.4%
top 41.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11

Description

Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages1 packages

NVDnextcloud/desktop< 3.1.3

Also affects: Debian Linux 10.0, 11.0

Patches

🔴Vulnerability Details

2
OSV
CVE-2021-22895: Nextcloud Desktop Client before 32021-06-11
CVEList
CVE-2021-22895: Nextcloud Desktop Client before 32021-06-11

📋Vendor Advisories

1
Debian
CVE-2021-22895: nextcloud-desktop - Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate vali...2021
CVE-2021-22895 — Improper Certificate Validation | cvebase