Описание
Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, target and cookies allows for an attacker to abuse the proxy endpoint to denial of service a third server. It is recommended that the Nextcloud Mail is upgraded to 2.2.8 or 3.3.0. There are no known workarounds for this vulnerability.
Ссылки
- Issue TrackingPatch
- Vendor Advisory
- Third Party Advisory
- Issue TrackingPatch
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.2.0 (включая) до 2.2.8 (исключая)Версия от 3.0.0 (включая) до 3.3.0 (исключая)
Одно из
cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*
EPSS
Процентиль: 33%
0.0013
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-918
EPSS
Процентиль: 33%
0.0013
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-918