Low severity3.9NVD Advisory· Published Nov 25, 2022· Updated Jun 17, 2026
CVE-2022-39334
CVE-2022-39334
Description
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes sensitive data or credentials to a network attacker. This affects the CLI only. It does not affect the standard GUI desktop Nextcloud clients, and it does not affect the Nextcloud server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords4 versionspkg:rpm/opensuse/nextcloud-desktop&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/nextcloud-desktop&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/nextcloud-desktop&distro=SUSE%20Package%20Hub%2015%20SP4pkg:rpm/suse/nextcloud-desktop&distro=SUSE%20Package%20Hub%2015%20SP5
< 3.8.0-bp154.2.3.1+ 3 more
- (no CPE)range: < 3.8.0-bp154.2.3.1
- (no CPE)range: < 3.8.0-bp155.2.3.1
- (no CPE)range: < 3.8.0-bp154.2.3.1
- (no CPE)range: < 3.8.0-bp155.2.3.1
- Range: < 3.6.1
Patches
Vulnerability mechanics
References
5- github.com/nextcloud/desktop/pull/5022nvdPatchThird Party Advisory
- github.com/nextcloud/desktop/issues/4927nvdExploitIssue TrackingThird Party Advisory
- github.com/nextcloud/security-advisories/security/advisories/GHSA-82xx-98xv-4jxvnvdThird Party Advisory
- hackerone.com/reports/1699740nvdPermissions RequiredThird Party Advisory
- lists.debian.org/debian-lts-announce/2025/09/msg00018.htmlnvd
News mentions
0No linked articles in our index yet.