Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
References
Link | Resource |
---|---|
https://github.com/nextcloud/mail/pull/8275 | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 | Vendor Advisory |
https://hackerone.com/reports/1913095 | Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 14:49
Type | Values Removed | Values Added |
---|---|---|
First Time |
Nextcloud mail
|
|
CPE | cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:* |
02 Jun 2023, 18:52
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 - Vendor Advisory | |
References | (MISC) https://github.com/nextcloud/mail/pull/8275 - Patch | |
References | (MISC) https://hackerone.com/reports/1913095 - Issue Tracking | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CPE | cpe:2.3:a:nextcloud:nextcloud_mail:*:*:*:*:*:*:*:* | |
CWE | CWE-918 |
27 May 2023, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-27 05:15
Updated : 2024-11-20 14:49
NVD link : CVE-2023-33184
Mitre link : CVE-2023-33184
CVE.ORG link : CVE-2023-33184
JSON object : View
Products Affected
nextcloud
CWE
CWE-918
Server-Side Request Forgery (SSRF)