Static Code Analysis (SAST) of Open Source Software
On behalf of the German Federal Office for Information Security (BSI), we examined the security of the open-source application Nextcloud using static code analysis and dynamic analysis (penetration tests). One vulnerability with an elevated risk potential and three vulnerabilities with a medium risk potential were discovered. Together with several other security-relevant problems, these were immediately reported to the developers and largely resolved. The project aims to improve the security of popular open-source software, especially for applications used by authorities or private users.
The analysis was carried out in spring/summer 2024 and published on February 6, 2025.
