Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31131

Опубликовано: 06 июл. 2022
Источник: nvd
CVSS3: 5.4
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users. It is recommended that the Nextcloud Mail app is upgraded to 1.12.2. There are no known workarounds for this issue. ### Workarounds No workaround available ### References * Pull request * HackerOne ### For more information If you have any questions or comments about this advisory: * Create a post in nextcloud/security-advisories * Customers: Open a support ticket at support.nextcloud.com

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nextcloud:nextcloud_mail:*:*:*:*:*:*:*:*
Версия до 1.12.2 (исключая)

EPSS

Процентиль: 37%
0.00163
Низкий

5.4 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-287
CWE-639

EPSS

Процентиль: 37%
0.00163
Низкий

5.4 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-287
CWE-639
Уязвимость CVE-2022-31131