Lucene search

K
nextcloudNick MarcoccioNC-SA-2020-030
HistoryJul 10, 2020 - 12:00 a.m.

Arbitrary code execution in desktop client via OpenSSL config (NC-SA-2020-030)

2020-07-1000:00:00
Nick Marcoccio
nextcloud.com
13

EPSS

0.001

Percentile

38.8%

A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.

EPSS

0.001

Percentile

38.8%