Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
References
Link | Resource |
---|---|
https://github.com/nextcloud/mail/pull/8275 | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 | Vendor Advisory |
https://hackerone.com/reports/1913095 | Issue Tracking |
https://github.com/nextcloud/mail/pull/8275 | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 | Vendor Advisory |
https://hackerone.com/reports/1913095 | Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:05
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.5 |
References | () https://github.com/nextcloud/mail/pull/8275 - Patch | |
References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 - Vendor Advisory | |
References | () https://hackerone.com/reports/1913095 - Issue Tracking |
20 Nov 2024, 14:49
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:* | |
First Time |
Nextcloud mail
|
02 Jun 2023, 18:52
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:nextcloud:nextcloud_mail:*:*:*:*:*:*:*:* | |
References | (MISC) https://hackerone.com/reports/1913095 - Issue Tracking | |
References | (MISC) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 - Vendor Advisory | |
References | (MISC) https://github.com/nextcloud/mail/pull/8275 - Patch | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
First Time |
Nextcloud nextcloud Mail
Nextcloud |
|
CWE | CWE-918 |
27 May 2023, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-27 05:15
Updated : 2024-11-21 08:05
NVD link : CVE-2023-33184
Mitre link : CVE-2023-33184
CVE.ORG link : CVE-2023-33184
JSON object : View
Products Affected
nextcloud
CWE
CWE-918
Server-Side Request Forgery (SSRF)