CVE-2023-48308
22.12.2023, 00:15
Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3Enginsight
Vendor | Product | Version |
---|---|---|
nextcloud | calendar | 3.0.0 ≤ 𝑥 < 4.5.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1258 - Exposure of Sensitive System Information Due to Uncleared Debug InformationThe hardware does not fully clear security-sensitive values, such as keys and intermediate values in cryptographic operations, when debug mode is entered.
- CWE-212 - Improper Removal of Sensitive Information Before Storage or TransferThe product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.