First published: Sat May 27 2023(Updated: )
Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Mail | >=2.2.0<2.2.5 | |
Nextcloud Nextcloud Mail | >=2.3.0<3.0.2 | |
Nextcloud Nextcloud Mail | >=1.13.0<1.15.3 | |
Nextcloud mail | >=1.13.0<1.15.3 | |
Nextcloud mail | >=2.2.0<2.2.5 | |
Nextcloud mail | >=2.3.0<3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33184 is a vulnerability in Nextcloud Mail that allows a blind SSRF attack to send GET requests to services running on the same web server.
CVE-2023-33184 allows an attacker to perform a blind SSRF attack on Nextcloud Mail, potentially accessing services on the same web server.
CVE-2023-33184 has a severity rating of 5.3, which is considered medium.
Nextcloud Mail versions between 2.2.0 and 2.2.5, 2.3.0 and 3.0.2, and 1.13.0 and 1.15.3 are affected by CVE-2023-33184.
To fix CVE-2023-33184, it is recommended to update the Mail app to version 3.02, 2.2.5, or 1.15.3.