CVE-2021-39220
Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP.
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images with a relative protocol. It is recommended that the Nextcloud Mail application is upgraded to 1.10.4 or 1.11.0. There are no known workarounds aside from upgrading.
- CVSS 3.1
- 3.5 LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-200
- Affected
- nextcloud/mail
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/mail/pull/5470Patch, Third Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6q9v-wm8r-rcv5Third Party Advisory
- https://hackerone.com/reports/1308147Permissions Required
- https://github.com/nextcloud/mail/pull/5470Patch, Third Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6q9v-wm8r-rcv5Third Party Advisory
- https://hackerone.com/reports/1308147Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.