PT-2021-15251 · Nextcloud+2 · Nextcloud Desktop Client+2

7A69

+1

·

Published

2021-04-14

·

Updated

2023-08-30

·

CVE-2021-22879

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nextcloud Desktop Client versions prior to 3.1.3
Description The issue is related to resource injection due to missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
Recommendations For Nextcloud Desktop Client versions prior to 3.1.3, update to version 3.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted servers to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-2019
ALT-PU-2023-4584
ALT-PU-2023-5197
CVE-2021-22879
OPENSUSE-SU-2021:0577-1
OPENSUSE-SU-2021_0577-1
OPENSUSE-SU-2024:11088-1

Affected Products

Alt Linux
Nextcloud Desktop Client
Suse