CVE-2021-22896: Medium severity Nextcloud Nextcloud vulnerability
Published Jun 11, 2021
·Updated
Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authenticated users to create mail aliases for other users.
Affected Software
1 affected component
Nextcloud Nextcloud<1.9.5
Remediation
Patch Available
Event History
Jun 11, 2021
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-22896.
2
What is the severity of CVE-2021-22896?
The severity of CVE-2021-22896 is medium with a score of 4.3.
3
What is the affected software by CVE-2021-22896?
The affected software is Nextcloud Mail before version 1.9.5.
4
What is the impact of CVE-2021-22896?
The impact of CVE-2021-22896 is that other authenticated users can create mail aliases for other users.
5
How can I fix CVE-2021-22896?
You can fix CVE-2021-22896 by updating Nextcloud Mail to version 1.9.5 or newer.