Debian 10694 Published by

A security update has been released for the next cloud desktop package in the Debian GNU/Linux 11 (Bullseye) LTS to fix multiple vulnerabilities. The vulnerabilities include the injection of arbitrary HTML into the desktop client application via notifications, user status, and information, as well as potential man-in-the-middle attacks and the exposure of sensitive data. Additionally, a malicious server administrator can recover and modify the contents of end-to-end encrypted files.

[SECURITY] [DLA 4303-1] nextcloud-desktop security update




[SECURITY] [DLA 4303-1] nextcloud-desktop security update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4303-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Abhijith PA
September 18, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : nextcloud-desktop
Version : 3.1.1-2+deb11u2
CVE ID : CVE-2022-39331 CVE-2022-39332 CVE-2022-39333 CVE-2022-39334
CVE-2023-28997

Multiple vulnerabilities were discovered in nextcloud-desktop,
nextcloud folder synchronization tool.

CVE-2022-39331

An attacker can inject arbitrary HyperText Markup Language into
the Desktop Client application in the notifications.

CVE-2022-39332

An attacker can inject arbitrary HyperText Markup Language into
the Desktop Client application via user status and information.

CVE-2022-39333

An attacker can inject arbitrary HyperText Markup Language into
the Desktop Client application.

CVE-2022-39334

A CLI utility called nextcloudcmd which is sometimes used for
automated scripting and headless servers would incorrectly trust
invalid TLS certificates, which may enable a Man-in-the-middle
attack that exposes sensitive data or credentials to a network
attacker.

CVE-2023-28997

A malicious server administrator can recover and modify the
contents of end-to-end encrypted files.

For Debian 11 bullseye, these problems have been fixed in version
3.1.1-2+deb11u2.

For Debian 11 bullseye, these problems have been fixed in version
3.1.1-2+deb11u2.

We recommend that you upgrade your nextcloud-desktop packages.

For the detailed security status of nextcloud-desktop please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nextcloud-desktop

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS