Vulnerability Description
Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Calendar | < 3.5.5 |
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/calendar/pull/4938Patch
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2792-2Vendor Advisory
- https://github.com/nextcloud/calendar/pull/4938Patch
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2792-2Vendor Advisory
FAQ
What is CVE-2023-33183?
CVE-2023-33183 is a vulnerability with a CVSS score of 2.6 (LOW). Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the...
How severe is CVE-2023-33183?
CVE-2023-33183 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-33183?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Calendar.