Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
References
Link | Resource |
---|---|
https://github.com/nextcloud/mail/pull/8275 | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564 | Vendor Advisory |
https://hackerone.com/reports/1913095 | Issue Tracking |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-05-27T04:36:01.535Z
Updated: 2023-05-27T04:36:01.535Z
Reserved: 2023-05-17T22:25:50.697Z
Link: CVE-2023-33184
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-05-27T05:15:09.980
Modified: 2023-06-02T18:52:18.290
Link: CVE-2023-33184
JSON object: View
Redhat Information
No data.
CWE