Medium severity5.9NVD Advisory· Published Jun 11, 2021· Updated Jun 17, 2026
CVE-2021-22895
CVE-2021-22895
Description
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- Nextcloud/Desktop Clientdescription
- Range: <3.3.1
Patches
Vulnerability mechanics
References
5- github.com/nextcloud/desktop/pull/2926nvdPatchThird Party Advisory
- hackerone.com/reports/903424nvdExploitIssue TrackingThird Party Advisory
- github.com/nextcloud/desktop/releases/tag/v3.1.3nvdRelease NotesThird Party Advisory
- github.com/nextcloud/security-advisories/security/advisories/GHSA-qpgp-vf4p-wcw5nvdThird Party Advisory
- www.debian.org/security/2021/dsa-4974nvdThird Party Advisory
News mentions
0No linked articles in our index yet.