First published: Mon May 08 2017(Updated: )
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | >=10.0.0<10.0.4 | |
Nextcloud Nextcloud Server | >=11.0.0<11.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-0895 is considered medium, as it allows for the disclosure of calendar and address book names.
To fix CVE-2017-0895, upgrade to Nextcloud Server version 10.0.4 or 11.0.2 or later.
Nextcloud Server versions prior to 10.0.4 and 11.0.2 are affected by CVE-2017-0895.
CVE-2017-0895 discloses the names of calendars and address books to other logged-in users.
No, CVE-2017-0895 does not disclose the actual content of the calendars and address books.