CVE-2023-33184: Blind SSRF in the Nextcloud Mail app on avatar endpoint
Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloud Mail appto a version that resolves this vulnerability.Fixed in 3.02 - Upgrade
Upgrade
Nextcloud Mail appto a version that resolves this vulnerability.Fixed in 2.2.5 - Upgrade
Upgrade
Nextcloud Mail appto a version that resolves this vulnerability.Fixed in 1.15.3
Event History
Frequently Asked Questions
What is CVE-2023-33184?
CVE-2023-33184 is a vulnerability in Nextcloud Mail that allows a blind SSRF attack to send GET requests to services running on the same web server.
How does CVE-2023-33184 impact Nextcloud Mail?
CVE-2023-33184 allows an attacker to perform a blind SSRF attack on Nextcloud Mail, potentially accessing services on the same web server.
What is the severity of CVE-2023-33184?
CVE-2023-33184 has a severity rating of 5.3, which is considered medium.
What software versions of Nextcloud Mail are affected by CVE-2023-33184?
Nextcloud Mail versions between 2.2.0 and 2.2.5, 2.3.0 and 3.0.2, and 1.13.0 and 1.15.3 are affected by CVE-2023-33184.
How can I fix CVE-2023-33184 in Nextcloud Mail?
To fix CVE-2023-33184, it is recommended to update the Mail app to version 3.02, 2.2.5, or 1.15.3.