Nextcloud Mail app vulnerable to Server-Side Request Forgery
CVE-2023-48307
What is CVE-2023-48307?
The Nextcloud Mail app, which serves as the email management tool for the self-hosted Nextcloud platform, exhibits a vulnerability that allows attackers to exploit an unprotected endpoint to conduct Server-Side Request Forgery (SSRF) attacks. This issue affects versions starting from 1.13.0 up to, but not including, versions 2.2.8 and 3.3.0. Users should transition to patched versions to mitigate this risk. As an interim measure, disabling the Mail app can help safeguard against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
security-advisories >= 1.13.0, < 2.2.8 < 1.13.0, 2.2.8
security-advisories >= 3.1.0, < 3.3.0 < 3.1.0, 3.3.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved