First published: Wed Apr 14 2021(Updated: )
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Desktop Client | <3.1.3 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22879 is a vulnerability in the Nextcloud Desktop Client prior to version 3.1.3 that allows a malicious server to execute remote commands by exploiting missing validation of URLs.
CVE-2021-22879 can be exploited by a malicious server to execute remote commands on the affected Nextcloud Desktop Client, potentially leading to unauthorized access or data manipulation.
CVE-2021-22879 has a severity rating of 8.8 (High) according to the CVSS (Common Vulnerability Scoring System).
Nextcloud Desktop Client versions up to exclusive version 3.1.3 are affected by CVE-2021-22879.
To fix CVE-2021-22879, users should update their Nextcloud Desktop Client to version 3.1.3 or later, which includes the necessary validation of URLs to prevent resource injection.