CVE-2023-33184

Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:05

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 3.5
References () https://github.com/nextcloud/mail/pull/8275 - Patch () https://github.com/nextcloud/mail/pull/8275 - Patch
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 - Vendor Advisory () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 - Vendor Advisory
References () https://hackerone.com/reports/1913095 - Issue Tracking () https://hackerone.com/reports/1913095 - Issue Tracking

20 Nov 2024, 14:49

Type Values Removed Values Added
CPE cpe:2.3:a:nextcloud:nextcloud_mail:*:*:*:*:*:*:*:* cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*
First Time Nextcloud mail

02 Jun 2023, 18:52

Type Values Removed Values Added
CPE cpe:2.3:a:nextcloud:nextcloud_mail:*:*:*:*:*:*:*:*
References (MISC) https://hackerone.com/reports/1913095 - (MISC) https://hackerone.com/reports/1913095 - Issue Tracking
References (MISC) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 - (MISC) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 - Vendor Advisory
References (MISC) https://github.com/nextcloud/mail/pull/8275 - (MISC) https://github.com/nextcloud/mail/pull/8275 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Nextcloud nextcloud Mail
Nextcloud
CWE CWE-918

27 May 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-27 05:15

Updated : 2024-11-21 08:05


NVD link : CVE-2023-33184

Mitre link : CVE-2023-33184

CVE.ORG link : CVE-2023-33184


JSON object : View

Products Affected

nextcloud

  • mail
CWE
CWE-918

Server-Side Request Forgery (SSRF)