CVE-2023-33184
Summary
| CVE | CVE-2023-33184 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-27 05:15:00 UTC |
| Updated | 2023-06-02 18:52:00 UTC |
| Description | Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nextcloud | Nextcloud Mail | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Blind SSRF in the Mail app on avatar endpoint · Advisory · nextcloud/security-advisories · GitHub | MISC | github.com | |
| fix(avatar): Validate favicon hosts by ChristophWurst · Pull Request #8275 · nextcloud/mail · GitHub | MISC | github.com | |
| HackerOne | MISC | hackerone.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.