[Bug 1205800] New: VUL-0: CVE-2022-39333: nextcloud-desktop: Arbitrary HyperText Markup Language injection in desktop client application
https://bugzilla.suse.com/show_bug.cgi?id=1205800 Bug ID: 1205800 Summary: VUL-0: CVE-2022-39333: nextcloud-desktop: Arbitrary HyperText Markup Language injection in desktop client application Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.4 Hardware: Other URL: https://smash.suse.de/issue/348941/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: ecsos@schirra.net Reporter: cathy.hu@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2022-39333 Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39333 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-92... https://www.cve.org/CVERecord?id=CVE-2022-39333 https://github.com/nextcloud/desktop/pull/4972 https://hackerone.com/reports/1711847 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1205800 https://bugzilla.suse.com/show_bug.cgi?id=1205800#c1 --- Comment #1 from Hu <cathy.hu@suse.com> --- Affected: - openSUSE:Backports:SLE-15-SP3/nextcloud-desktop 3.1.3 - openSUSE:Backports:SLE-15-SP4/nextcloud-desktop 3.3.6 Not Affected: - openSUSE:Factory/nextcloud-desktop 3.6.2 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1205800 Maintenance Automation <maint-coord+maintenance-robot@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com