CVE-2021-22879: High severity nextcloud desktop client vulnerability
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-22879?
CVE-2021-22879 is a vulnerability in the Nextcloud Desktop Client prior to version 3.1.3 that allows a malicious server to execute remote commands by exploiting missing validation of URLs.
How does CVE-2021-22879 impact users?
CVE-2021-22879 can be exploited by a malicious server to execute remote commands on the affected Nextcloud Desktop Client, potentially leading to unauthorized access or data manipulation.
What is the severity of CVE-2021-22879?
CVE-2021-22879 has a severity rating of 8.8 (High) according to the CVSS (Common Vulnerability Scoring System).
Which software versions are affected by CVE-2021-22879?
Nextcloud Desktop Client versions up to exclusive version 3.1.3 are affected by CVE-2021-22879.
How can CVE-2021-22879 be fixed?
To fix CVE-2021-22879, users should update their Nextcloud Desktop Client to version 3.1.3 or later, which includes the necessary validation of URLs to prevent resource injection.