Fedora Account System
Red Hat Associate
Red Hat Customer
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow. Reference: https://github.com/nextcloud/desktop/releases/tag/v3.1.3 https://hackerone.com/reports/903424 https://github.com/nextcloud/desktop/pull/2926 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qpgp-vf4p-wcw5
Created nextcloud-client tracking bugs for this issue: Affects: epel-8 [bug 1975118] Affects: fedora-all [bug 1975117]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.