Описание
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| nextcloud-desktop | not-affected | package |
Примечания
https://nextcloud.com/security/advisory/?id=NC-SA-2020-030
https://hackerone.com/reports/622170
EPSS
Процентиль: 41%
0.00188
Низкий
Связанные уязвимости
CVSS3: 7.8
nvd
больше 5 лет назад
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
CVSS3: 7.8
github
больше 3 лет назад
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
EPSS
Процентиль: 41%
0.00188
Низкий