Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-23942

Опубликовано: 06 фев. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 5.4

Описание

The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer. Versions prior to 3.6.3 are missing sanitisation on qml labels which are used for basic HTML elements such as strong, em and head lines in the UI of the desktop client. The lack of sanitisation may allow for javascript injection. It is recommended that the Nextcloud Desktop Client is upgraded to 3.6.3. There are no known workarounds for this issue.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

3.7.0-2
esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

not-affected

3.7.0-2
focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

kinetic

ignored

end of life, was needs-triage
lunar

not-affected

3.7.0-2
mantic

not-affected

3.7.0-2

Показывать по

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer. Versions prior to 3.6.3 are missing sanitisation on qml labels which are used for basic HTML elements such as `strong`, `em` and `head` lines in the UI of the desktop client. The lack of sanitisation may allow for javascript injection. It is recommended that the Nextcloud Desktop Client is upgraded to 3.6.3. There are no known workarounds for this issue.

CVSS3: 5.4
debian
около 3 лет назад

The Nextcloud Desktop Client is a tool to synchronize files from a Nex ...

suse-cvrf
больше 2 лет назад

Security update for nextcloud-desktop

suse-cvrf
почти 3 года назад

Security update for nextcloud-desktop

5.4 Medium

CVSS3