CVE-2024-52508 HIGH

CVE-2024-52508: Nextcloud Mail auto configurator can be tricked into sending account information to wrong servers

Vendor Nextcloud
Product security-advisories
Weakness CWE-200 · Info exposure
Published November 15, 2024
Last update November 15, 2024

CVSS base score

8.2/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L

What the vulnerability does

01Description

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an email address like user@example.tld that does not support auto configuration, and an attacker managed to register autoconfig.tld, the used email details would be send to the server of the attacker. It is recommended that the Nextcloud Mail app is upgraded to 1.14.6, 1.15.4, 2.2.11, 3.6.3, 3.7.7 or 4.0.0.

Key dates

02Disclosure timeline

November 15, 2024 CVE published
November 15, 2024 Record updated