Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
2017-05-08T20:29:00.367
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 3.5 (LOW)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nextcloud | nextcloud_server | < 10.0.4 | Yes |
Application | nextcloud | nextcloud_server | < 11.0.2 | Yes |