Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow. Reference: https://github.com/nextcloud/desktop/releases/tag/v3.1.3 https://hackerone.com/reports/903424 https://github.com/nextcloud/desktop/pull/2926 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qpgp-vf4p-wcw5
Created nextcloud-client tracking bugs for this issue: Affects: epel-8 [bug 1975118] Affects: fedora-all [bug 1975117]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.