CVE-2023-33183: Error in calendar when booking an appointment reveals the full path of the website
Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloud Calendar appto a version that resolves this vulnerability.Fixed in 3.5.5 - Upgrade
Upgrade
Nextcloud Calendar appto a version that resolves this vulnerability.Fixed in 4.2.3
Event History
Frequently Asked Questions
What is CVE-2023-33183?
CVE-2023-33183 is a vulnerability in the Calendar app for Nextcloud that allows disclosure of internal paths when the SMTP server is unavailable.
How can I protect my Nextcloud Calendar app from CVE-2023-33183?
To protect your Nextcloud Calendar app from CVE-2023-33183, it is recommended to update to version 3.5.5 or 4.2.3.
What is the severity of CVE-2023-33183?
The severity of CVE-2023-33183 is medium, with a severity value of 4.3.
Where can I find more information about CVE-2023-33183?
You can find more information about CVE-2023-33183 in the following references: [GitHub Pull Request](https://github.com/nextcloud/calendar/pull/4938) and [Nextcloud Security Advisories](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2792-2734-hr7j).
What is the Common Weakness Enumeration (CWE) of CVE-2023-33183?
The CWE of CVE-2023-33183 is CWE-285, which is improper authorization.