CVE-2021-39220Improper Input Validation in Security-advisories

Severity
3.5LOWNVD
EPSS
0.3%
top 50.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25

Description

Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images with a relative protocol. It is recommended that the Nextcloud Mail application is upgraded to 1.10.4 or 1.11.0. There are no known workarounds aside from upgrading.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NExploitability: 2.1 | Impact: 1.4

Affected Packages2 packages

NVDnextcloud/mail< 1.10.4
CVEListV5nextcloud/security-advisories< 1.10.4, < 1.11.0

Patches

🔴Vulnerability Details

1
CVEList
Bypass of image blocking in Nextcloud Mail2021-10-25
CVE-2021-39220 — Improper Input Validation | cvebase