Nextcloud Mail 3.2.0

CPE Details

Nextcloud Mail 3.2.0
3.2.0
2023-10-19
15h41 +00:00
2024-11-20
13h49 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:nextcloud:mail:3.2.0:*:*:*:*:*:*:*

Informations

Vendor

nextcloud

Product

mail

Version

3.2.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-48307 2023-11-21 22h22 +00:00 Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, an attacker can use an unprotected endpoint in the Mail app to perform a SSRF attack. Nextcloud Mail app versions 2.2.8 and 3.3.0 contain a patch for this issue. As a workaround, disable the mail app.
9.8
Critical
CVE-2023-45660 2023-10-16 18h32 +00:00 Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, target and cookies allows for an attacker to abuse the proxy endpoint to denial of service a third server. It is recommended that the Nextcloud Mail is upgraded to 2.2.8 or 3.3.0. There are no known workarounds for this vulnerability.
4.3
Medium