PT-2023-6404 · Nextcloud+1 · Nextcloud Calendar+1
Whoisshuvam
·
Publicado
2023-07-09
·
Atualizado
2023-10-20
·
CVE-2023-45150
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Nextcloud Calendar app versions prior to 4.4.4
Description
The issue is related to missing precondition checks in the Nextcloud calendar app, which causes the server to attempt validation of strings of any length as email addresses. This can lead to the server becoming busy and unresponsive, potentially allowing a remote attacker to cause a denial of service.
Recommendations
For versions prior to 4.4.4, upgrade the Nextcloud Calendar app to 4.4.4.
As a temporary workaround for users unable to upgrade, disable the calendar app.
Exploit
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Nextcloud Calendar
Red Os