First published: Fri Mar 20 2020(Updated: )
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | <15.0.14 | |
Nextcloud Nextcloud Server | >=16.0.0<16.0.7 | |
Nextcloud Nextcloud Server | >=17.0.0<17.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.