PT-2021-22471 · Nextcloud · Nextcloud Mail

Mihkelraba

·

Published

2021-10-25

·

Updated

2022-08-05

·

CVE-2021-39220

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Mail versions prior to 1.10.4 and 1.11.0
Description The Nextcloud Mail application has a privacy filter issue that fails to filter images with a relative protocol, potentially leaking the read state or user IP. This issue is due to the default behavior of not rendering images in emails.
Recommendations For versions prior to 1.10.4, upgrade to version 1.10.4. For versions prior to 1.11.0, upgrade to version 1.11.0. As a temporary workaround, consider disabling image rendering in emails until a patch is available.

Fix

Information Disclosure

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-39220
GHSA-6Q9V-WM8R-RCV5

Affected Products

Nextcloud Mail