Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
{
"binaries": [
{
"binary_name": "caja-nextcloud",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "dolphin-nextcloud",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "libnextcloudsync-dev",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "libnextcloudsync0",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nautilus-nextcloud",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nemo-nextcloud",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nextcloud-desktop",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nextcloud-desktop-cmd",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nextcloud-desktop-common",
"binary_version": "2.6.2-1build1"
},
{
"binary_name": "nextcloud-desktop-l10n",
"binary_version": "2.6.2-1build1"
}
]
}
{
"binaries": [
{
"binary_name": "caja-nextcloud",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "dolphin-nextcloud",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "libnextcloudsync-dev",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "libnextcloudsync0",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nautilus-nextcloud",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nemo-nextcloud",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nextcloud-desktop",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nextcloud-desktop-cmd",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nextcloud-desktop-common",
"binary_version": "3.4.2-1ubuntu1"
},
{
"binary_name": "nextcloud-desktop-l10n",
"binary_version": "3.4.2-1ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "caja-nextcloud",
"binary_version": "3.11.0-1.1build4"
},
{
"binary_name": "dolphin-nextcloud",
"binary_version": "3.11.0-1.1build4"
},
{
"binary_name": "libnextcloudsync-dev",
"binary_version": "3.11.0-1.1build4"
},
{
"binary_name": "libnextcloudsync0t64",
"binary_version": "3.11.0-1.1build4"
},
{
"binary_name": "nautilus-nextcloud",
"binary_version": "3.11.0-1.1build4"
},
{
"binary_name": "nemo-nextcloud",
"binary_version": "3.11.0-1.1build4"
},
{
"binary_name": "nextcloud-desktop",
"binary_version": "3.11.0-1.1build4"
},
{
"binary_name": "nextcloud-desktop-cmd",
"binary_version": "3.11.0-1.1build4"
},
{
"binary_name": "nextcloud-desktop-common",
"binary_version": "3.11.0-1.1build4"
},
{
"binary_name": "nextcloud-desktop-l10n",
"binary_version": "3.11.0-1.1build4"
}
]
}
{
"binaries": [
{
"binary_name": "caja-nextcloud",
"binary_version": "3.16.6-3"
},
{
"binary_name": "dolphin-nextcloud",
"binary_version": "3.16.6-3"
},
{
"binary_name": "libnextcloudsync-dev",
"binary_version": "3.16.6-3"
},
{
"binary_name": "libnextcloudsync0t64",
"binary_version": "3.16.6-3"
},
{
"binary_name": "nautilus-nextcloud",
"binary_version": "3.16.6-3"
},
{
"binary_name": "nemo-nextcloud",
"binary_version": "3.16.6-3"
},
{
"binary_name": "nextcloud-desktop",
"binary_version": "3.16.6-3"
},
{
"binary_name": "nextcloud-desktop-cmd",
"binary_version": "3.16.6-3"
},
{
"binary_name": "nextcloud-desktop-common",
"binary_version": "3.16.6-3"
},
{
"binary_name": "nextcloud-desktop-l10n",
"binary_version": "3.16.6-3"
}
]
}
{
"binaries": [
{
"binary_name": "caja-nextcloud",
"binary_version": "3.16.0-1"
},
{
"binary_name": "dolphin-nextcloud",
"binary_version": "3.16.0-1"
},
{
"binary_name": "libnextcloudsync-dev",
"binary_version": "3.16.0-1"
},
{
"binary_name": "libnextcloudsync0t64",
"binary_version": "3.16.0-1"
},
{
"binary_name": "nautilus-nextcloud",
"binary_version": "3.16.0-1"
},
{
"binary_name": "nemo-nextcloud",
"binary_version": "3.16.0-1"
},
{
"binary_name": "nextcloud-desktop",
"binary_version": "3.16.0-1"
},
{
"binary_name": "nextcloud-desktop-cmd",
"binary_version": "3.16.0-1"
},
{
"binary_name": "nextcloud-desktop-common",
"binary_version": "3.16.0-1"
},
{
"binary_name": "nextcloud-desktop-l10n",
"binary_version": "3.16.0-1"
}
]
}