CVE-2021-22895: Medium severity Nextcloud Desktop vulnerability
Published Jun 11, 2021
·Updated
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
Affected Software
4 affected componentsFixes available
debian/nextcloud-desktop
2.5.1-3+deb10u23.1.1-2+deb11u13.7.3-13.10.0-1
Nextcloud Desktop<3.1.3
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Jun 11, 2021
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
DescriptionWeakness
Jun 14, 2021
Data Sourced
06:57 PM
SeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-22895?
CVE-2021-22895 is a vulnerability in the Nextcloud Desktop Client that allows improper certificate validation.
2
How does CVE-2021-22895 affect Nextcloud Desktop Client?
CVE-2021-22895 affects Nextcloud Desktop Client versions before 3.3.1.
3
What is the severity of CVE-2021-22895?
The severity of CVE-2021-22895 is high with a CVSS score of 5.9.
4
How can I fix CVE-2021-22895?
To fix CVE-2021-22895, update Nextcloud Desktop Client to version 3.3.1 or later.
5
Where can I find more information about CVE-2021-22895?
You can find more information about CVE-2021-22895 on the Nextcloud Desktop Client GitHub page and the Nextcloud security advisories website.