Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
References
Link | Resource |
---|---|
https://github.com/nextcloud/mail/pull/8275 | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 | Vendor Advisory |
https://hackerone.com/reports/1913095 | Issue Tracking |
https://github.com/nextcloud/mail/pull/8275 | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 | Vendor Advisory |
https://hackerone.com/reports/1913095 | Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-05-27 05:15
Updated : 2024-11-21 08:05
NVD link : CVE-2023-33184
Mitre link : CVE-2023-33184
CVE.ORG link : CVE-2023-33184
JSON object : View
Products Affected
nextcloud
CWE
CWE-918
Server-Side Request Forgery (SSRF)