PT-2021-19830 · Nextcloud · Nextcloud Mail
Kesselb
·
Published
2021-06-01
·
Updated
2024-11-20
·
CVE-2021-32652
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nextcloud Mail versions prior to 1.4.3
Nextcloud Mail versions prior to 1.8.2
Description
A missing permission check in Nextcloud Mail allows another authenticated user to access mail metadata of other users.
Recommendations
For versions prior to 1.4.3, update to version 1.4.3 or later to resolve the issue.
For versions prior to 1.8.2, update to version 1.8.2 or later to resolve the issue.
Exploit
Fix
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Mail