PT-2023-6404 · Nextcloud+1 · Nextcloud Calendar+1

Whoisshuvam

·

Publicado

2023-07-09

·

Atualizado

2023-10-20

·

CVE-2023-45150

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud Calendar app versions prior to 4.4.4
Description The issue is related to missing precondition checks in the Nextcloud calendar app, which causes the server to attempt validation of strings of any length as email addresses. This can lead to the server becoming busy and unresponsive, potentially allowing a remote attacker to cause a denial of service.
Recommendations For versions prior to 4.4.4, upgrade the Nextcloud Calendar app to 4.4.4. As a temporary workaround for users unable to upgrade, disable the calendar app.

Exploit

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07118
CVE-2023-45150
GHSA-R936-8GWM-W452

Produtos afetados

Nextcloud Calendar
Red Os