CVE-2021-32707
Bypass of image blocking in Nextcloud Mail
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by default, render images in emails to not leak the read state. The privacy filter failed to filter images with a `background-image` CSS attribute. Note that the images were still passed through the Nextcloud image proxy, and thus there was no IP leakage. The issue was patched in version 1.9.6 and 1.10.0. No workarounds are known to exist.
Nextcloud Mail es una aplicación de correo para Nextcloud. En versiones anteriores a 1.9.6, la aplicación Nextcloud Mail no renderiza, por defecto, las imágenes en los correos electrónicos para no filtrar el estado de lectura. El filtro de privacidad produce un fallo en filtrar las imágenes con un atributo CSS "background-image". Nótese que las imágenes seguían pasando mediante el proxy de imágenes de Nextcloud, y por lo tanto no había ningún filtrado de IP. El problema fue parcheado en versiones 1.9.6 y 1.10.0. No se conoce ninguna solución
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-12 CVE Reserved
- 2021-07-12 CVE Published
- 2023-10-04 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xxp4-44xc-8crh | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://hackerone.com/reports/1215251 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/nextcloud/mail/pull/5189 | 2022-10-25 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Nextcloud Mail Search vendor "Nextcloud" for product "Nextcloud Mail" | < 1.9.6 Search vendor "Nextcloud" for product "Nextcloud Mail" and version " < 1.9.6" | - |
Affected
|