PT-2026-95208 · Nextcloud · Nextcloud
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud (affected versions not specified)
Description
Remote-instance signature verification in Circles fetches the
keyId URL provided by an attacker before trust is established. This process explicitly allows local or private addresses, bypassing core Server-Side Request Forgery (SSRF) protections. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location. The public, unauthenticated endpoints 'POST /apps/circles/event/' and 'POST /apps/circles/incoming/' reach this code path, enabling any unauthenticated user to force the server to issue a GET request to an internal address. This is a blind SSRF, meaning the response body is not returned to the requester, but an attacker can still determine if an internal service is reachable.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcloud