First published: Thu Dec 21 2023(Updated: )
Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Calendar | >=3.0.0<4.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48308 has been classified as a moderate security vulnerability.
To fix CVE-2023-48308, upgrade the Nextcloud Calendar app to version 4.5.3 or later.
CVE-2023-48308 affects versions of the Nextcloud Calendar app from 3.0.0 to 4.5.2.
An attacker can gain access to stacktrace data and internal server paths when generating an exception.
Yes, upgrading to Nextcloud Calendar app version 4.5.3 or higher is recommended to mitigate the vulnerability.