PT-2023-6404 · Nextcloud+1 · Nextcloud Calendar+1
Whoisshuvam
·
Published
2023-07-09
·
Updated
2023-10-20
·
CVE-2023-45150
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Nextcloud Calendar app versions prior to 4.4.4
Description
The issue is related to missing precondition checks in the Nextcloud calendar app, which causes the server to attempt validation of strings of any length as email addresses. This can lead to the server becoming busy and unresponsive, potentially allowing a remote attacker to cause a denial of service.
Recommendations
For versions prior to 4.4.4, upgrade the Nextcloud Calendar app to 4.4.4.
As a temporary workaround for users unable to upgrade, disable the calendar app.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Calendar
Red Os