Bug ID 1207976
Summary VUL-0: CVE-2023-23942: nextcloud-desktop: missing sanitisation on qml labels leading to javascript injection
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/356329/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee ecsos@schirra.net
Reporter thomas.leroy@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2023-23942

The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud
Server with your computer. Versions prior to 3.6.3 are missing sanitisation on
qml labels which are used for basic HTML elements such as `strong`, `em` and
`head` lines in the UI of the desktop client. The lack of sanitisation may
allow
for javascript injection. It is recommended that the Nextcloud Desktop Client
is
upgraded to 3.6.3. There are no known workarounds for this issue.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-23942
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-64qc-vf6v-8xgg
https://www.cve.org/CVERecord?id=CVE-2023-23942
https://github.com/nextcloud/desktop/pull/5233
https://hackerone.com/reports/1788598


You are receiving this mail because: