Add your offcanvas content in here

The Company

Simplifying your IT-security journey.

Knowledge & News

Security of Nextcloud Analyzed for the BSI

February 7, 2025 |
Tags: SAST
Kategorie: News Publication

Static Code Analysis (SAST) of Open Source Software

On behalf of the German Federal Office for Information Security (BSI), we examined the security of the open-source application Nextcloud using static code analysis and dynamic analysis (penetration tests). One vulnerability with an elevated risk potential and three vulnerabilities with a medium risk potential were discovered. Together with several other security-relevant problems, these were immediately reported to the developers and largely resolved. The project aims to improve the security of popular open-source software, especially for applications used by authorities or private users.

The analysis was carried out in spring/summer 2024 and published on February 6, 2025.

BSI Report
Article on Heise Online
Further Security Analyses

The Author

Mirko Richter

Mirko Richter is a Software Security Consultant, Source Code Analysis Specialist and Training Manager for basic training courses up to advanced coding and Secure SDLC training. He has been involved in software development, architecture and security since the mid-90s. He is a speaker at conferences and author of several technical articles.