Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY2 SECURITY RECORDS

Publisher not identified

Nextcloud Mail

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2021-22896 11 Jun 2021 Fixed in 1.9.5 The Cyber Centre recommends organizations review all impacted F5 appliances and virtual deployments and patch to one of the below recommended versions. [ 1 ] BIG-IP: Versions 16.0.0 to 16.0.1 should be upgraded to 16.0.1.1 Versions 15.1.0 to 15.1.2 should be upgraded to 15.1.2.1 Versions 14.1.0 to 14.1.3.1 should be upgraded to 14.1.4 Versions 13.1.0 to 13.1.3.5 should be upgraded to 13.1.3.6 Versions 12.1.0 to 12.1.5.2 should be upgraded to 12.1.5.3 Versions 11.6.1 to 11.6.5.2 should be upgraded to 11.6.5.3 BIG-IQ: Version 8.0.0 is unaffected Versions 7.1.0 to 7.1.0.2 should be upgraded to 8.0.0 Versions 7.0.0 to 7.0.0.1 should be upgraded to 7.1.0.3 Versions 6.0.0 to 6.1.0 should be upgraded to 7.0.0.2 F5 indicates that if a fixed version has not been identified for a branch used by an organization then no update is available. F5 recommends that organizations upgrade to a version with an available patch. Organizations may use the F5 platform matrix to determine compatible software versions for their F5 platform. [ 1 ] While the Cyber Centre strongly encourages patching as soon as possible, administrators should consider applying the mitigations described in the F5 KB articles if patching is not immediately possible. See the [ 4 ] and [ 5 ] for more details. In summary: Block iControl REST access through the self IP address. Block iControl REST access through the management interface. Block Configuration utility access through self IP addresses. Block Configuration utility access through the management interface. Patching as described in this section also fixes the buffer overflow vulnerabilities described in the previous section. There are no mitigations against CVE-2021-22991 other than patching, while for CVE-2021-22992 F5 has provided an iRule mitigation. [ 9 ] In all cases, the Cyber Centre and F5 recommend patching as the primary mitigation. Update reference ↗
CVE-2020-8156 12 May 2020 1.1.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.