CVE-2021-32707
Dashboard / Vulnerabilities / CVE-2021-32707
Summary:
Details: Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by default, render images in emails to not leak the read state. The privacy filter failed to filter images with a `background-image` CSS attribute. Note that the images were still passed through the Nextcloud image proxy, and thus there was no IP leakage. The issue was patched in version 1.9.6 and 1.10.0. No workarounds are known to exist.
References: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xxp4-44xc-8crh, https://github.com/nextcloud/mail/pull/5189, https://hackerone.com/reports/1215251
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v1.9.5
v1.9.4
v1.9.3
v1.9.2
v1.9.1
v1.9.0
v1.9.0-alpha3
v1.9.0-alpha2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
