Lucene search

K
nextcloudNextcloudGHSA-M45F-R5GH-H6CX
HistoryFeb 13, 2023 - 1:47 p.m.

IDOR Vulnerability in Nextcloud Mail

2023-02-1313:47:28
github.com
40
idor vulnerability
nextcloud mail
mailbox access
software update
hackerone
pull request

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

38.9%

Description

Impact

An attacker can access the mail box by ID getting the subjects and the first characters of the emails.

Patches

Users should update to

Mail 2.2.1 for Nextcloud 25
Mail 1.14.5 for Nextcloud 22-24
Mail 1.12.9 for Nextcloud 21
Mail 1.11.8 for Nextcloud 20

Workarounds

No workaround available

References

HackerOne
Pull Request

For more information

If you have any questions or comments about this advisory:

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

38.9%

Related for GHSA-M45F-R5GH-H6CX