CVE-2021-32652: Missing permission check on email metadata retrieval
Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1.8.2 allows another authenticated users to access mail metadata of other users. Versions 1.4.3 and 1.8.2 contain patches for this vulnerability; no workarounds other than the patches are known to exist.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32652?
CVE-2021-32652 is a vulnerability in Nextcloud Mail that allows authenticated users to access mail metadata of other users.
What is the severity of CVE-2021-32652?
The severity of CVE-2021-32652 is high with a severity value of 4.3.
How can CVE-2021-32652 be exploited?
CVE-2021-32652 can be exploited by another authenticated user to gain access to mail metadata of other users.
Which versions of Nextcloud Mail are affected by CVE-2021-32652?
Versions up to 1.4.3 and versions between 1.5.5 and 1.8.2 of Nextcloud Mail are affected by CVE-2021-32652.
How can I fix CVE-2021-32652?
To fix CVE-2021-32652, update Nextcloud Mail to version 1.4.3 or apply the patch provided in versions 1.4.3 and 1.8.2.