High severity8.8NVD Advisory· Published Apr 14, 2021· Updated Jun 17, 2026
CVE-2021-22879
CVE-2021-22879
Description
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- Nextcloud/Desktop Clientdescription
- Range: <3.1.3
- osv-coordsRange: < 3.1.3-lp152.2.6.1
Patches
Vulnerability mechanics
References
5- github.com/nextcloud/desktop/pull/2906nvdPatchThird Party Advisory
- hackerone.com/reports/1078002nvdExploitThird Party Advisory
- nextcloud.com/security/advisory/nvdVendor Advisory
- security.gentoo.org/glsa/202105-37nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTWBJAS5DJJIK7LLVBZZQTSJASUVIRVE/nvd
News mentions
0No linked articles in our index yet.