You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Mail app does not respect download permissions in shares
Low
nickvergessen
published
GHSA-pwpp-fvcr-w862Nov 15, 2024
Package
Mail
(Nextcloud)
Affected versions
>=2.2.0, >= 3.6.0, >= 3.7.0
Patched versions
2.2.10, 3.6.2, 3.7.2
Description
Impact
The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to themselves and then downloading it from their mail clients.
Patches
It is recommended that the Nextcloud Mail is upgraded to 2.2.10, 3.6.2 or 3.7.2
Impact
The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to themselves and then downloading it from their mail clients.
Patches
It is recommended that the Nextcloud Mail is upgraded to 2.2.10, 3.6.2 or 3.7.2
Workarounds
References
For more information
If you have any questions or comments about this advisory: