MEDIUM
Blind SSRF via server URL input in the Nextcloud Mail app
Published Feb 6, 2023
5.0
MEDIUMCVSS 3.1
EPSS 0.92%
Description
Nextcloud mail is an email app for the nextcloud home server platform. In affected versions the SMTP, IMAP and Sieve host fields allowed to scan for internal services and servers reachable from within the local network of the Nextcloud Server. It is recommended that the Nextcloud Maill app is upgraded to 1.15.0 or 2.2.2. The only known workaround for this issue is to completely disable the nextcloud mail app.
Affected products
-
- Version < 1.15.0StatusaffectedConstraints-
- Version >= 2.0.0, < 2.2.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Nextcloud | Security-Advisories | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-28009 Advisory
- https://github.com/nextcloud/mail/pull/7796 x_refsource_MISCPatch
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gcx-r739-9pf6 x_refsource_CONFIRMVendor Advisory
- https://hackerone.com/reports/1736390 x_refsource_MISCExploitThird Party Advisory
- https://hackerone.com/reports/1741525 x_refsource_MISCExploitThird Party Advisory
- https://hackerone.com/reports/1746582 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-28009 | Advisory | |
| https://github.com/nextcloud/mail/pull/7796 | x_refsource_MISCPatch | |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gcx-r739-9pf6 | x_refsource_CONFIRMVendor Advisory | |
| https://hackerone.com/reports/1736390 | x_refsource_MISCExploitThird Party Advisory | |
| https://hackerone.com/reports/1741525 | x_refsource_MISCExploitThird Party Advisory | |
| https://hackerone.com/reports/1746582 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Feb 6, 2023
Updated Mar 10, 2025
Reserved Jan 19, 2023
Link CVE-2023-23943
CISA Vulnrichment
Updated Mar 10, 2025
ENISA EUVD
EUVD-2023-28009 Assigner GitHub_M
Published Feb 6, 2023
Updated Mar 10, 2025
Exploited since n/a
Link EUVD-2023-28009