CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
Percentile
56.7%
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate
validation due to lack of SSL certificate verification when using the
“Register with a Provider” flow.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 20.04 | noarch | nextcloud-desktop | < any | UNKNOWN |
ubuntu | 22.04 | noarch | nextcloud-desktop | < any | UNKNOWN |
ubuntu | 24.04 | noarch | nextcloud-desktop | < any | UNKNOWN |
github.com/nextcloud/desktop/commit/b1ddd0e491b2af0ed040e658d8bcde2a7a61c9fc (stable-3.1)
github.com/nextcloud/desktop/pull/2926
github.com/nextcloud/desktop/releases/tag/v3.1.3
github.com/nextcloud/security-advisories/security/advisories/GHSA-qpgp-vf4p-wcw5
hackerone.com/reports/903424
launchpad.net/bugs/cve/CVE-2021-22895
nvd.nist.gov/vuln/detail/CVE-2021-22895
security-tracker.debian.org/tracker/CVE-2021-22895
www.cve.org/CVERecord?id=CVE-2021-22895
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
Percentile
56.7%