VulnerabilityModified
CVE-2023-33184
A blind SSRF attack allowed to send GET requests to services running in the same web server.
MEDIUM 5.3EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- nextcloud/mail
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/mail/pull/8275Patch
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564Vendor Advisory
- https://hackerone.com/reports/1913095Issue Tracking
- https://github.com/nextcloud/mail/pull/8275Patch
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gph-9895-w564Vendor Advisory
- https://hackerone.com/reports/1913095Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.