Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-22879

Опубликовано: 14 апр. 2021
Источник: debian
EPSS Низкий

Описание

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nextcloud-desktopfixed3.1.1-2package
nextcloud-desktopno-dsabusterpackage

Примечания

  • https://nextcloud.com/security/advisory/?id=NC-SA-2021-008

  • https://github.com/nextcloud/desktop/pull/2906

EPSS

Процентиль: 83%
0.01853
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 5 лет назад

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

CVSS3: 8.8
nvd
почти 5 лет назад

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

suse-cvrf
почти 5 лет назад

Security update for nextcloud-desktop

CVSS3: 8.8
github
больше 3 лет назад

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

EPSS

Процентиль: 83%
0.01853
Низкий