Skip to content

Calendar app returns full stacktrace when an error happens while editing appointment

Low
nickvergessen published GHSA-fv3c-qvjr-5rv8 Dec 18, 2023

Package

Calendar (Nextcloud)

Affected versions

>= 3.0.0

Patched versions

4.5.3

Description

Impact

An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment.

Patches

It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3

Workarounds

  • Disable calendar app

References

For more information

If you have any questions or comments about this advisory:

Severity

Low
3.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

CVE ID

CVE-2023-48308

Weaknesses

Credits