{"id":"openSUSE-SU-2023:0171-1","summary":"Security update for nextcloud-desktop","details":"This update for nextcloud-desktop fixes the following issues:\n\nUpdate ot 3.8.0\n\n  - Resize WebView widget once the loginpage rendered\n  - Feature/secure file drop\n  - Check German translation for wrong wording\n  - L10n: Correct word\n  - Fix displaying of file details button for local syncfileitem activities\n  - Improve config upgrade warning dialog\n  - Only accept folder setup page if overrideLocalDir is set\n  - Update CHANGELOG.\n  - Prevent ShareModel crash from accessing bad pointers\n  - Bugfix/init value for pointers\n  - Log to stdout when built in Debug config\n  - Clean up account creation and deletion code\n  - L10n: Added dot to end of sentence\n  - L10n: Fixed grammar\n  - Fix 'Create new folder' menu entries in settings not working correctly on macOS\n  - Ci/clang tidy checks init variables\n  - Fix share dialog infinite loading\n  - Fix edit locally job not finding the user account: wrong user id\n  - Skip e2e encrypted files with empty filename in metadata\n  - Use new connect syntax\n  - Fix avatars not showing up in settings dialog account actions until clicked on\n  - Always discover blacklisted folders to avoid data loss when modifying selectivesync list.\n  - Fix infinite loading in the share dialog when public link shares are disabled on the server\n  - With cfapi when dehydrating files add missing flag\n  - Fix text labels in Sync Status component\n  - Display 'Search globally' as the last sharees list element\n  - Fix display of 2FA notification.\n  - Bugfix/do not restore virtual files\n  - Show server name in tray main window\n  - Add Ubuntu Lunar\n  - Debian build classification 'beta' cannot override 'release'.\n  - Update changelog\n  - Follow shouldNotify flag to hide notifications when needed\n  - Bugfix/stop after creating config file\n  - E2EE cut extra zeroes from derypted byte array.\n  - When local sync folder is overriden, respect this choice\n  - Feature/e2ee fixes\n\n- This update also fixes security issues:\n\n  - (boo#1205798, CVE-2022-39331)\n    - Arbitrary HyperText Markup Language injection in notifications \n  - (boo#1205799, CVE-2022-39332)\n    - Arbitrary HyperText Markup Language injection in user status and information \n  - (boo#1205800, CVE-2022-39333)\n    - Arbitrary HyperText Markup Language injection in desktop client application \n  - (boo#1205801, CVE-2022-39334)\n    - Client incorrectly trusts invalid TLS certificates \n  - (boo#1207976, CVE-2023-23942)\n    - missing sanitisation on qml labels leading to javascript injection \n","modified":"2026-03-11T07:33:29.769654Z","published":"2023-07-10T11:03:58Z","related":["CVE-2022-39331","CVE-2022-39332","CVE-2022-39333","CVE-2022-39334","CVE-2023-23942"],"upstream":["CVE-2022-39331","CVE-2022-39332","CVE-2022-39333","CVE-2022-39334","CVE-2023-23942"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MYOV4BMU2LQGVZ5NTYTI7BA3XMRNOCDF/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205799"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205800"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205801"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207976"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-39331"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-39332"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-39333"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-39334"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-23942"}],"affected":[{"package":{"name":"nextcloud-desktop","ecosystem":"SUSE:Package Hub 15 SP5","purl":"pkg:rpm/suse/nextcloud-desktop&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.0-bp155.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"nextcloud-desktop-doc":"3.8.0-bp155.2.3.1","nextcloud-desktop-dolphin":"3.8.0-bp155.2.3.1","nextcloud-desktop":"3.8.0-bp155.2.3.1","caja-extension-nextcloud":"3.8.0-bp155.2.3.1","nextcloud-desktop-lang":"3.8.0-bp155.2.3.1","cloudproviders-extension-nextcloud":"3.8.0-bp155.2.3.1","libnextcloudsync-devel":"3.8.0-bp155.2.3.1","libnextcloudsync0":"3.8.0-bp155.2.3.1","nautilus-extension-nextcloud":"3.8.0-bp155.2.3.1","nemo-extension-nextcloud":"3.8.0-bp155.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0171-1.json"}},{"package":{"name":"nextcloud-desktop","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/nextcloud-desktop&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.0-bp155.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"caja-extension-nextcloud":"3.8.0-bp155.2.3.1","libnextcloudsync0":"3.8.0-bp155.2.3.1","nautilus-extension-nextcloud":"3.8.0-bp155.2.3.1","nextcloud-desktop-doc":"3.8.0-bp155.2.3.1","nextcloud-desktop-lang":"3.8.0-bp155.2.3.1","nextcloud-desktop":"3.8.0-bp155.2.3.1","cloudproviders-extension-nextcloud":"3.8.0-bp155.2.3.1","libnextcloudsync-devel":"3.8.0-bp155.2.3.1","nemo-extension-nextcloud":"3.8.0-bp155.2.3.1","nextcloud-desktop-dolphin":"3.8.0-bp155.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0171-1.json"}}],"schema_version":"1.7.5"}