diff --git a/2022/31xxx/CVE-2022-31131.json b/2022/31xxx/CVE-2022-31131.json index 9f62557b0a1..7ebf098d6bd 100644 --- a/2022/31xxx/CVE-2022-31131.json +++ b/2022/31xxx/CVE-2022-31131.json @@ -1,18 +1,93 @@ { - "data_type": "CVE", - "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { + "ASSIGNER": "security-advisories@github.com", "ID": "CVE-2022-31131", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "STATE": "PUBLIC", + "TITLE": "Ownership check missing when updating or deleting mail attachments in Nextcloud mail" }, + "affects": { + "vendor": { + "vendor_data": [ + { + "product": { + "product_data": [ + { + "product_name": "security-advisories", + "version": { + "version_data": [ + { + "version_value": "< 1.12.2" + } + ] + } + } + ] + }, + "vendor_name": "nextcloud" + } + ] + } + }, + "data_format": "MITRE", + "data_type": "CVE", + "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users. It is recommended that the Nextcloud Mail app is upgraded to 1.12.2. There are no known workarounds for this issue.\n\n### Workarounds\nNo workaround available\n\n### References\n* [Pull request](https://github.com/nextcloud/mail/pull/6600)\n* [HackerOne](https://hackerone.com/reports/1579820)\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Create a post in [nextcloud/security-advisories](https://github.com/nextcloud/security-advisories/discussions)\n* Customers: Open a support ticket at [support.nextcloud.com](https://support.nextcloud.com)\n" } ] + }, + "impact": { + "cvss": { + "attackComplexity": "LOW", + "attackVector": "NETWORK", + "availabilityImpact": "NONE", + "baseScore": 5.4, + "baseSeverity": "MEDIUM", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "privilegesRequired": "LOW", + "scope": "UNCHANGED", + "userInteraction": "NONE", + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", + "version": "3.1" + } + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "CWE-287: Improper Authentication" + } + ] + } + ] + }, + "references": { + "reference_data": [ + { + "name": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xhv7-5mhv-299j", + "refsource": "CONFIRM", + "url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xhv7-5mhv-299j" + }, + { + "name": "https://github.com/nextcloud/mail/pull/6600", + "refsource": "MISC", + "url": "https://github.com/nextcloud/mail/pull/6600" + }, + { + "name": "https://github.com/nextcloud/mail/pull/6600/commits/6dd2527be8d4f6788b449c8a8f5577628b990605", + "refsource": "MISC", + "url": "https://github.com/nextcloud/mail/pull/6600/commits/6dd2527be8d4f6788b449c8a8f5577628b990605" + } + ] + }, + "source": { + "advisory": "GHSA-xhv7-5mhv-299j", + "discovery": "UNKNOWN" } } \ No newline at end of file