PT-2021-19873 · Nextcloud · Nextcloud Mail

·

CVE-2021-32707

·

Published

2021-07-12

·

Updated

2024-11-20

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Mail versions prior to 1.9.6
Description The Nextcloud Mail application has an issue where the privacy filter fails to filter images with a background-image CSS attribute, potentially leaking the read state. However, images are still passed through the Nextcloud image proxy, preventing IP leakage.
Recommendations For versions prior to 1.9.6, update to version 1.9.6 or 1.10.0 to resolve the issue. At the moment, there is no information about other workarounds for this issue.

Exploit

Fix

Information Disclosure

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32707
GHSA-XXP4-44XC-8CRH

Affected Products

Nextcloud Mail