CVE-2022-39334

NameCVE-2022-39334
DescriptionNextcloud desktop is the desktop sync client for Nextcloud. Versions prior to 3.6.1 would incorrectly trust invalid TLS certificates. A Man-in-the-middle attack is possible in case a user can be made running a nextcloudcmd CLI command locally. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this vulnerability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nextcloud-desktop (PTS)buster, buster (security)2.5.1-3+deb10u2vulnerable
bullseye (security), bullseye3.1.1-2+deb11u1vulnerable
bookworm, sid3.6.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nextcloud-desktopsource(unstable)3.6.1-1

Notes

[bullseye] - nextcloud-desktop <no-dsa> (Minor issue)
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-82xx-98xv-4jxv
https://github.com/nextcloud/desktop/issues/4927
https://github.com/nextcloud/desktop/pull/5022

Search for package or bug name: Reporting problems