CVE-2023-48308: Calendar app returns full stacktrace when an error happens while editing appointment
Published Dec 21, 2023
·Updated
Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3
Affected Software
1 affected component
Nextcloud calendar>=3.0.0<4.5.3
Remediation
Patch Available
Event History
Dec 21, 2023
CVE Published
11:12 PM
Data Sourced
11:12 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-48308?
CVE-2023-48308 has been classified as a moderate security vulnerability.
2
How do I fix CVE-2023-48308?
To fix CVE-2023-48308, upgrade the Nextcloud Calendar app to version 4.5.3 or later.
3
What types of systems are affected by CVE-2023-48308?
CVE-2023-48308 affects versions of the Nextcloud Calendar app from 3.0.0 to 4.5.2.
4
What kind of information can an attacker access through CVE-2023-48308?
An attacker can gain access to stacktrace data and internal server paths when generating an exception.
5
Is there a recommended version for the Nextcloud Calendar app to mitigate CVE-2023-48308?
Yes, upgrading to Nextcloud Calendar app version 4.5.3 or higher is recommended to mitigate the vulnerability.