Unrated severityNVD Advisory· Published Nov 25, 2022· Updated Nov 3, 2025
nextcloudcmd incorrectly trusts bad TLS certificates
CVE-2022-39334
Description
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes sensitive data or credentials to a network attacker. This affects the CLI only. It does not affect the standard GUI desktop Nextcloud clients, and it does not affect the Nextcloud server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords4 versionspkg:rpm/opensuse/nextcloud-desktop&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/nextcloud-desktop&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/nextcloud-desktop&distro=SUSE%20Package%20Hub%2015%20SP4pkg:rpm/suse/nextcloud-desktop&distro=SUSE%20Package%20Hub%2015%20SP5
< 3.8.0-bp154.2.3.1+ 3 more
- (no CPE)range: < 3.8.0-bp154.2.3.1
- (no CPE)range: < 3.8.0-bp155.2.3.1
- (no CPE)range: < 3.8.0-bp154.2.3.1
- (no CPE)range: < 3.8.0-bp155.2.3.1
- nextcloud/security-advisoriesv5Range: < 3.6.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.