Bug ID 1205800
Summary VUL-0: CVE-2022-39333: nextcloud-desktop: Arbitrary HyperText Markup Language injection in desktop client application
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/348941/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee ecsos@schirra.net
Reporter cathy.hu@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2022-39333

Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can
inject arbitrary HyperText Markup Language into the Desktop Client application.
It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There
are no known workarounds for this issue.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39333
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-92p9-x79h-2mj8
https://www.cve.org/CVERecord?id=CVE-2022-39333
https://github.com/nextcloud/desktop/pull/4972
https://hackerone.com/reports/1711847


You are receiving this mail because: