Related Vulnerabilities: CVE-2021-22895  

Nextcloud Desktop Client before 3.3.1 wasn't verifying the SSL certificates when using the "Register with a Provider" flow.

Severity Medium

Remote Yes

Type Certificate verification bypass

Description

Nextcloud Desktop Client before 3.3.1 wasn't verifying the SSL certificates when using the "Register with a Provider" flow.

AVG-2025 nextcloud-client 3.2.1-1 Medium Vulnerable

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qpgp-vf4p-wcw5
https://hackerone.com/reports/903424