PT-2021-19830 · Nextcloud · Nextcloud Mail

Kesselb

·

Published

2021-06-01

·

Updated

2024-11-20

·

CVE-2021-32652

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nextcloud Mail versions prior to 1.4.3 Nextcloud Mail versions prior to 1.8.2
Description A missing permission check in Nextcloud Mail allows another authenticated user to access mail metadata of other users.
Recommendations For versions prior to 1.4.3, update to version 1.4.3 or later to resolve the issue. For versions prior to 1.8.2, update to version 1.8.2 or later to resolve the issue.

Exploit

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-32652
GHSA-MXX2-6RG9-V2VC

Affected Products

Nextcloud Mail