PT-2021-19873 · Nextcloud · Nextcloud Mail

Foobar7

·

Published

2021-07-12

·

Updated

2024-11-20

·

CVE-2021-32707

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Mail versions prior to 1.9.6
Description The Nextcloud Mail application has an issue where the privacy filter fails to filter images with a background-image CSS attribute, potentially leaking the read state. However, images are still passed through the Nextcloud image proxy, preventing IP leakage.
Recommendations For versions prior to 1.9.6, update to version 1.9.6 or 1.10.0 to resolve the issue. At the moment, there is no information about other workarounds for this issue.

Exploit

Fix

Information Disclosure

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-32707
GHSA-XXP4-44XC-8CRH

Affected Products

Nextcloud Mail