CVE-2022-39334
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless serv
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes sensitive data or credentials to a network attacker. This affects the CLI only.
It does not affect the standard GUI desktop Nextcloud clients, and it does not affect the Nextcloud server.
LOW · CVSS 3.9
EPSS 0.00065
Schedule remediation
- Public exploit or PoC is available
Sigma rules6
YARA rules0