PT-2017-10695 · Nextcloud · Nextcloud Server

Lukas Reschke

+1

·

Published

2017-05-08

·

Updated

2022-09-27

·

CVE-2017-0894

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Server versions prior to 11.0.3
Description The issue is related to a logical error that leads to the disclosure of valid share tokens for public calendars. This could potentially allow an attacker to access publicly shared calendars without knowing the share token.
Recommendations For versions prior to 11.0.3, update to version 11.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to publicly shared calendars until the update is applied.

Fix

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2017-0894

Affected Products

Nextcloud Server