Lucene search

K
cvelistHackeroneCVELIST:CVE-2021-22879
HistoryApr 14, 2021 - 12:41 p.m.

CVE-2021-22879

2021-04-1412:41:24
CWE-99
hackerone
www.cve.org
2

9 High

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.1%

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

CNA Affected

[
  {
    "product": "Nextcloud Desktop Client",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in 3.1.3"
      }
    ]
  }
]

9 High

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.1%