PT-2023-6404 · Nextcloud+1 · Nextcloud Calendar+1

Whoisshuvam

·

Published

2023-07-09

·

Updated

2023-10-20

·

CVE-2023-45150

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud Calendar app versions prior to 4.4.4
Description The issue is related to missing precondition checks in the Nextcloud calendar app, which causes the server to attempt validation of strings of any length as email addresses. This can lead to the server becoming busy and unresponsive, potentially allowing a remote attacker to cause a denial of service.
Recommendations For versions prior to 4.4.4, upgrade the Nextcloud Calendar app to 4.4.4. As a temporary workaround for users unable to upgrade, disable the calendar app.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2023-07118
CVE-2023-45150
GHSA-R936-8GWM-W452

Affected Products

Nextcloud Calendar
Red Os