Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrvw-x9cv-3j76

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

EPSS

Процентиль: 83%
0.01853
Низкий

8.8 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 5 лет назад

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

CVSS3: 8.8
nvd
почти 5 лет назад

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

CVSS3: 8.8
debian
почти 5 лет назад

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource inje ...

suse-cvrf
почти 5 лет назад

Security update for nextcloud-desktop

EPSS

Процентиль: 83%
0.01853
Низкий

8.8 High

CVSS3

Дефекты

CWE-74