VYPR
Unrated severityNVD Advisory· Published Oct 25, 2021· Updated Aug 4, 2024

Bypass of image blocking in Nextcloud Mail

CVE-2021-39220

Description

Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images with a relative protocol. It is recommended that the Nextcloud Mail application is upgraded to 1.10.4 or 1.11.0. There are no known workarounds aside from upgrading.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Nextcloud/Mailllm-fuzzy
    Range: <1.10.4 || <1.11.0
  • nextcloud/security-advisoriesv5
    Range: < 1.10.4, < 1.11.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.