CVE-2023-33184

Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-05-27 05:15

Updated : 2024-11-21 08:05


NVD link : CVE-2023-33184

Mitre link : CVE-2023-33184

CVE.ORG link : CVE-2023-33184


JSON object : View

Products Affected

nextcloud

  • mail
CWE
CWE-918

Server-Side Request Forgery (SSRF)