PT-2021-19873 · Nextcloud · Nextcloud Mail
Foobar7
·
Published
2021-07-12
·
Updated
2024-11-20
·
CVE-2021-32707
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Mail versions prior to 1.9.6
Description
The Nextcloud Mail application has an issue where the privacy filter fails to filter images with a
background-image CSS attribute, potentially leaking the read state. However, images are still passed through the Nextcloud image proxy, preventing IP leakage.Recommendations
For versions prior to 1.9.6, update to version 1.9.6 or 1.10.0 to resolve the issue.
At the moment, there is no information about other workarounds for this issue.
Exploit
Fix
Information Disclosure
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Mail