Skip to content

SSL certificate was not validated in Provider Registration Flow

Moderate
LukasReschke published GHSA-qpgp-vf4p-wcw5 Jun 1, 2021

Package

Nextcloud Desktop Client

Affected versions

< 3.1.3

Patched versions

3.1.3

Description

Impact

Nextcloud Desktop Client before 3.1.3 wasn't verifying the SSL certificates when using the "Register with a Provider" flow.

Patches

It is recommended that the Nextcloud Desktop Client is upgraded to 3.1.3.

Workarounds

None.

References

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2021-22895

Weaknesses

Credits