A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.
2020-03-20T21:15:17.547
2024-11-21T05:38:22.020
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nextcloud | nextcloud_server | < 15.0.14 | Yes |
Application | nextcloud | nextcloud_server | < 16.0.7 | Yes |
Application | nextcloud | nextcloud_server | < 17.0.2 | Yes |