Lucene search

K
nextcloudNextcloudGHSA-JMGP-77JQ-FJP3
HistoryMay 31, 2021 - 3:51 p.m.

Alias creation did not validate account ID

2021-05-3115:51:17
github.com
22
nextcloud mail
account id
permission check
authenticated users
mail aliases
security advisory.

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

38.9%

Description

Impact

Missing permission check in Nextcloud Mail before 1.9.5 allows another authenticated users to create mail aliases for other users.

Patches

It is recommended that the Nextcloud Mail App is upgraded to 1.9.5.

Workarounds

None.

References

For more information

If you have any questions or comments about this advisory:

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

38.9%

Related for GHSA-JMGP-77JQ-FJP3