[Bug 1205799] New: VUL-0: CVE-2022-39332: nextcloud-deskop: Arbitrary HyperText Markup Language injection in user status and information
https://bugzilla.suse.com/show_bug.cgi?id=1205799 Bug ID: 1205799 Summary: VUL-0: CVE-2022-39332: nextcloud-deskop: Arbitrary HyperText Markup Language injection in user status and information Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.4 Hardware: Other URL: https://smash.suse.de/issue/348942/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: ecsos@schirra.net Reporter: cathy.hu@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2022-39332 Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application via user status and information. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39332 https://www.cve.org/CVERecord?id=CVE-2022-39332 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q9... https://github.com/nextcloud/desktop/pull/4972 https://hackerone.com/reports/1707977 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1205799 https://bugzilla.suse.com/show_bug.cgi?id=1205799#c1 --- Comment #1 from Hu <cathy.hu@suse.com> --- Affected: - openSUSE:Backports:SLE-15-SP3/nextcloud-desktop 3.1.3 - openSUSE:Backports:SLE-15-SP4/nextcloud-desktop 3.3.6 Not Affected: - openSUSE:Factory/nextcloud-desktop 3.6.2 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1205799 Maintenance Automation <maint-coord+maintenance-robot@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com