GHSA-mx8q-jqwm-85mv
Dashboard / Vulnerabilities / GHSA-mx8q-jqwm-85mv
Summary: NocoDB information disclosure vulnerability
Details: In NocoDB prior to 0.91.7, the SMTP plugin doesn't have verification or validation. This allows attackers to make requests to internal servers and read the contents.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-2062, https://github.com/nocodb/nocodb/commit/a18f5dd53811b9ec1c1bb2fdbfb328c0c87d7fb4, https://github.com/nocodb/nocodb, https://huntr.dev/bounties/35593b4c-f127-4699-8ad3-f0b2203a8ef6
Affected packages
Package
Name: nocodb
Purl: pkg:npm/nocodb
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.91.7
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
