Unrated severityNVD Advisory· Published Oct 25, 2021· Updated Aug 4, 2024
Bypass of image blocking in Nextcloud Mail
CVE-2021-39220
Description
Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images with a relative protocol. It is recommended that the Nextcloud Mail application is upgraded to 1.10.4 or 1.11.0. There are no known workarounds aside from upgrading.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- nextcloud/security-advisoriesv5Range: < 1.10.4, < 1.11.0
Patches
Vulnerability mechanics
References
3- github.com/nextcloud/mail/pull/5470mitrex_refsource_MISC
- github.com/nextcloud/security-advisories/security/advisories/GHSA-6q9v-wm8r-rcv5mitrex_refsource_CONFIRM
- hackerone.com/reports/1308147mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.