{"id":"openSUSE-SU-2021:0577-1","summary":"Security update for nextcloud-desktop","details":"This update for nextcloud-desktop fixes the following issues:\n\nnextcloud-desktop was updated to 3.1.3:\n\n- desktop#2884 [stable-3.1] Add support for Hirsute\n- desktop#2920 [stable-3.1] Validate sensitive URLs to onle allow http(s) schemes.\n- desktop#2926 [stable-3.1] Validate the providers ssl certificate\n- desktop#2939 Bump release to 3.1.3\n\nThis also fix security issues:\n\n- (boo#1184770, CVE-2021-22879, NC-SA-2021-008 , CWE-99)\n\n  Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource\n  injection by way of missing validation of URLs, allowing a \n  malicious server to execute remote commands.\n  User interaction is needed for exploitation. \n","modified":"2026-03-11T07:33:00.737337Z","published":"2021-04-19T12:08:02Z","related":["CVE-2021-22879"],"upstream":["CVE-2021-22879"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YL7MF53UDFP75PXEIEPNXBAJQBN6ZIBB/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184770"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-22879"}],"affected":[{"package":{"name":"nextcloud-desktop","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/nextcloud-desktop&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-lp152.2.6.1"}]}],"ecosystem_specific":{"binaries":[{"libnextcloudsync-devel":"3.1.3-lp152.2.6.1","libnextcloudsync0":"3.1.3-lp152.2.6.1","nextcloud-desktop-doc":"3.1.3-lp152.2.6.1","nextcloud-desktop":"3.1.3-lp152.2.6.1","caja-extension-nextcloud":"3.1.3-lp152.2.6.1","nautilus-extension-nextcloud":"3.1.3-lp152.2.6.1","nemo-extension-nextcloud":"3.1.3-lp152.2.6.1","nextcloud-desktop-dolphin":"3.1.3-lp152.2.6.1","nextcloud-desktop-lang":"3.1.3-lp152.2.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0577-1.json"}}],"schema_version":"1.7.5"}