CVE-2021-39220 Information
Jun 07, 2022
cve
Description
Nextcloud is an open-source self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images with a relative protocol. It is recommended that the Nextcloud Mail application is upgraded to 1.10.4 or 1.11.0. There are no known workarounds aside from upgrading.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Reference
https://github.com/nextcloud/mail/pull/5470 https://hackerone.com/reports/1308147 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6q9v-wm8r-rcv5
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
3.5
Share on: