CVE-2017-0895: Infoleak
Published May 8, 2017
·Updated
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
Affected Software
2 affected components
Nextcloud Server>=10.0.0<10.0.4
Nextcloud Server>=11.0.0<11.0.2
Event History
May 8, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-0895?
The severity of CVE-2017-0895 is considered medium, as it allows for the disclosure of calendar and address book names.
2
How do I fix CVE-2017-0895?
To fix CVE-2017-0895, upgrade to Nextcloud Server version 10.0.4 or 11.0.2 or later.
3
What versions of Nextcloud Server are affected by CVE-2017-0895?
Nextcloud Server versions prior to 10.0.4 and 11.0.2 are affected by CVE-2017-0895.
4
What type of information is disclosed in CVE-2017-0895?
CVE-2017-0895 discloses the names of calendars and address books to other logged-in users.
5
Is the actual content of calendars and address books disclosed in CVE-2017-0895?
No, CVE-2017-0895 does not disclose the actual content of the calendars and address books.