First published: Fri Jun 11 2021(Updated: )
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/nextcloud-desktop | 2.5.1-3+deb10u2 3.1.1-2+deb11u1 3.7.3-1 3.10.0-1 | |
Nextcloud Desktop | <3.1.3 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22895 is a vulnerability in the Nextcloud Desktop Client that allows improper certificate validation.
CVE-2021-22895 affects Nextcloud Desktop Client versions before 3.3.1.
The severity of CVE-2021-22895 is high with a CVSS score of 5.9.
To fix CVE-2021-22895, update Nextcloud Desktop Client to version 3.3.1 or later.
You can find more information about CVE-2021-22895 on the Nextcloud Desktop Client GitHub page and the Nextcloud security advisories website.