Bug ID 1207977
Summary VUL-0: CVE-2023-23943: nextcloud: IMAP and Sieve host fields allowed to scan for internal services and servers reachable from within the local network
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/356328/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee ecsos@schirra.net
Reporter thomas.leroy@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2023-23943

Nextcloud mail is an email app for the nextcloud home server platform. In
affected versions the SMTP, IMAP and Sieve host fields allowed to scan for
internal services and servers reachable from within the local network of the
Nextcloud Server. It is recommended that the Nextcloud Maill app is upgraded to
1.15.0 or 2.2.2. The only known workaround for this issue is to completely
disable the nextcloud mail app.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-23943
https://www.cve.org/CVERecord?id=CVE-2023-23943
https://github.com/nextcloud/mail/pull/7796
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8gcx-r739-9pf6
https://hackerone.com/reports/1741525
https://hackerone.com/reports/1736390
https://hackerone.com/reports/1746582


You are receiving this mail because: