CVE-2022-39334
published 2022-11-25CVE-2022-39334: Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to…
PriorityP419medium4.7CVSS 3.1
AVLACHPRLUINSUCNIHAN
EPSS
0.20%
10.1th percentile
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes sensitive data or credentials to a network attacker. This affects the CLI only. It does not affect the standard GUI desktop Nextcloud clients, and it does not affect the Nextcloud server.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nextcloud-desktop | < nextcloud-desktop 3.6.1-1 (bookworm) | nextcloud-desktop 3.6.1-1 (bookworm) |
| nextcloud | desktop | < 3.6.1 | 3.6.1 |
| nextcloud | security-advisories | < 3.6.1 | 3.6.1 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
osv4.7MEDIUM
vendor_debian3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-39334: Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers
osv·2022-11-25·CVSS 4.7
CVE-2022-39334 [MEDIUM] CVE-2022-39334: Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes sensitive data or credentials to a network attacker. This affects the CLI only. It does not affect the standard GUI desktop Nextcloud clients, and it does not affect the Nextcloud server.
Debian
CVE-2022-39334: nextcloud-desktop - Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used f...
vendor_debian·2022·CVSS 3.9
CVE-2022-39334 [LOW] CVE-2022-39334: nextcloud-desktop - Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used f...
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes sensitive data or credentials to a network attacker. This affects the CLI only. It does not affect the standard GUI desktop Nextcloud clients, and it does not affect the Nextcloud server.
Scope: local
bookworm: resolved (fixed in 3.6.1-1)
bullseye: resolved (fixed in 3.1.1-2+deb11u2)
forky: resolved (fixed in 3.6.1-1)
sid: resolved (fixed in 3.6.1-1)
trixie: resolved (fixed in 3.6.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/nextcloud/desktop/issues/4927https://github.com/nextcloud/desktop/pull/5022https://github.com/nextcloud/security-advisories/security/advisories/GHSA-82xx-98xv-4jxvhttps://hackerone.com/reports/1699740https://github.com/nextcloud/desktop/issues/4927https://github.com/nextcloud/desktop/pull/5022https://github.com/nextcloud/security-advisories/security/advisories/GHSA-82xx-98xv-4jxvhttps://hackerone.com/reports/1699740https://lists.debian.org/debian-lts-announce/2025/09/msg00018.html
2022-11-25
Published