Mail auto configurator sends account information to `autoconfig.tld` server when no auto-configuration is possible
Package
Mail
(Nextcloud)
Affected versions
>= 1.9.0, >= 2.1.0, >= 3.1.0
Patched versions
1.14.6, 1.15.4, 2.2.11, 3.6.3, 3.7.7, 4.0.0
Impact
When a user is trying to set up a mail account with an email address like
user@example.tld
that does not support auto configuration, and an attacker managed to registerautoconfig.tld
, the used email details would be send to the server of the attacker. Registeringautoconfig.tld
is not possible for most of the tlds, especially.com
,.de
, and the like.Patches
It is recommended that the Nextcloud Mail app is upgraded to 1.14.6, 1.15.4, 2.2.11, 3.6.3, 3.7.7 or 4.0.0
Workarounds
References
For more information
If you have any questions or comments about this advisory: