Add CVE-2022-31131 for GHSA-xhv7-5mhv-299j

Add CVE-2022-31131 for GHSA-xhv7-5mhv-299j
This commit is contained in:
advisory-database[bot] 2022-07-06 17:52:10 +00:00 committed by GitHub
parent 846a8bcc7a
commit beb76b291b
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -1,18 +1,93 @@
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ASSIGNER": "security-advisories@github.com",
"ID": "CVE-2022-31131",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"STATE": "PUBLIC",
"TITLE": "Ownership check missing when updating or deleting mail attachments in Nextcloud mail"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "security-advisories",
"version": {
"version_data": [
{
"version_value": "< 1.12.2"
}
]
}
}
]
},
"vendor_name": "nextcloud"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users. It is recommended that the Nextcloud Mail app is upgraded to 1.12.2. There are no known workarounds for this issue.\n\n### Workarounds\nNo workaround available\n\n### References\n* [Pull request](https://github.com/nextcloud/mail/pull/6600)\n* [HackerOne](https://hackerone.com/reports/1579820)\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Create a post in [nextcloud/security-advisories](https://github.com/nextcloud/security-advisories/discussions)\n* Customers: Open a support ticket at [support.nextcloud.com](https://support.nextcloud.com)\n"
}
]
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-287: Improper Authentication"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xhv7-5mhv-299j",
"refsource": "CONFIRM",
"url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xhv7-5mhv-299j"
},
{
"name": "https://github.com/nextcloud/mail/pull/6600",
"refsource": "MISC",
"url": "https://github.com/nextcloud/mail/pull/6600"
},
{
"name": "https://github.com/nextcloud/mail/pull/6600/commits/6dd2527be8d4f6788b449c8a8f5577628b990605",
"refsource": "MISC",
"url": "https://github.com/nextcloud/mail/pull/6600/commits/6dd2527be8d4f6788b449c8a8f5577628b990605"
}
]
},
"source": {
"advisory": "GHSA-xhv7-5mhv-299j",
"discovery": "UNKNOWN"
}
}