CVE-2021-32707 – Bypass of image blocking in Nextcloud Mail
https://notcve.org/view.php?id=CVE-2021-32707
Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by default, render images in emails to not leak the read state. The privacy filter failed to filter images with a `background-image` CSS attribute. Note that the images were still passed through the Nextcloud image proxy, and thus there was no IP leakage. The issue was patched in version 1.9.6 and 1.10.0. • https://github.com/nextcloud/mail/pull/5189 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xxp4-44xc-8crh https://hackerone.com/reports/1215251 • CWE-20: Improper Input Validation CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2021-32652 – Missing permission check on email metadata retrieval
https://notcve.org/view.php?id=CVE-2021-32652
Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1.8.2 allows another authenticated users to access mail metadata of other users. Versions 1.4.3 and 1.8.2 contain patches for this vulnerability; no workarounds other than the patches are known to exist. Nextcloud Mail es una aplicación de correo para la plataforma Nextcloud. Una falta de comprobación de permisos en Nextcloud Mail versiones anteriores a 1.4.3 y 1.8.2, permite a otro usuario autentificado acceder a los metadatos de correo de otros usuarios. • https://github.com/nextcloud/security-advisories/security/advisories/GHSA-mxx2-6rg9-v2vc https://hackerone.com/reports/1094063 • CWE-284: Improper Access Control CWE-862: Missing Authorization •
CVE-2020-8156
https://notcve.org/view.php?id=CVE-2020-8156
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. Una falta de verificación del host TLS en Nextcloud Mail versión 1.1.3, permitió un ataque de tipo man-in-the-middle. • https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KC6HLX5SG4PZO6Y54D2LFJ4ATG76BKOP https://nextcloud.com/security/advisory/?id=NC-SA-2020-020 • CWE-295: Improper Certificate Validation •