Vulnerability Description
Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Calendar | >= 3.0.0, < 4.5.3 |
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/calendar/pull/5553PatchVendor Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-fv3c-qVendor Advisory
- https://github.com/nextcloud/calendar/pull/5553PatchVendor Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-fv3c-qVendor Advisory
FAQ
What is CVE-2023-48308?
CVE-2023-48308 is a vulnerability with a CVSS score of 3.5 (LOW). Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is rec...
How severe is CVE-2023-48308?
CVE-2023-48308 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-48308?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Calendar.