3.5

CVE-2022-31014

Exploit

SMTP Command Injection in iCalendar Attachments to emails via newlines in Nextcloud Server

SMTP Command Injection in iCalendar Attachments to emails via newlines

Nextcloud server is an open source personal cloud server. Affected versions were found to be vulnerable to SMTP command injection. The impact varies based on which commands are supported by the backend SMTP server. However, the main risk here is that the attacker can then hijack an already-authenticated SMTP session and run arbitrary SMTP commands as the email user, such as sending emails to other users, changing the FROM user, and so on. As before, this depends on the configuration of the server itself, but newlines should be sanitized to mitigate such arbitrary SMTP command injection. It is recommended that the Nextcloud Server is upgraded to 22.2.8 , 23.0.5 or 24.0.1. There are no known workarounds for this issue.
Mögliche Gegenmaßnahme
Server: No workaround available
Enterprise Server: No workaround available
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextcloud ≫ Nextcloud Server SwEdition enterprise Version < 19.0.13.7
Nextcloud ≫ Nextcloud Server Version < 22.2.8
Nextcloud ≫ Nextcloud Server SwEdition enterprise Version >= 20.0.0 < 20.0.14.6
Nextcloud ≫ Nextcloud Server SwEdition enterprise Version >= 21.0.0 < 21.0.9.5
Nextcloud ≫ Nextcloud Server Version >= 23.0.0 < 23.0.5
Nextcloud ≫ Nextcloud Server Version 24.0.0 Update -
Nextcloud ≫ Nextcloud Server Version 24.0.0 Update beta1
Nextcloud ≫ Nextcloud Server Version 24.0.0 Update beta2
Nextcloud ≫ Nextcloud Server Version 24.0.0 Update beta3
Nextcloud ≫ Nextcloud Server Version 24.0.0 Update rc1
Nextcloud ≫ Nextcloud Server Version 24.0.0 Update rc2
Nextcloud ≫ Nextcloud Server Version 24.0.0 Update rc3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemNextcloud
≫
Produkt Server
Version >= 0.0.0, < 22.2.8
Version >= 23.0.0, < 23.0.5
Version >= 24.0.0, < 24.0.1
SystemNextcloud
≫
Produkt Enterprise Server
Version >= 0.0.0, < 19.0.13.7
Version >= 20.0.0, < 20.0.14.6
Version >= 21.0.0, < 21.0.9.5
Version >= 22.2.0, < 22.2.8
Version >= 23.0.0, < 23.0.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.48% 0.829
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
security-advisories@github.com 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-264h-3v4w-6xh2
Third Party Advisory
Exploit
https://github.com/nextcloud/server/pull/32428
Patch
Third Party Advisory
Issue Tracking
https://hackerone.com/reports/1516377
Patch
Third Party Advisory
Exploit
Issue Tracking
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-264h-3v4w-6xh2
Third Party Advisory