A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NNextcloud Desktop
APPNextcloud< 2.6.5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2024-46958CRITICAL9.1PL ✓same product
Nextcloud Desktop Client — błędne uprawnienia zsynchronizowanych plików na Linux
CVE-2021-37617HIGH7.3same product
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextclo...
CVE-2021-22879HIGH8.8same product
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of UR...
CVE-2020-8224HIGH7.8same product
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious Ope...
CVE-2025-47792MEDIUM5.0same product
Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3r...