VulnerabilityModified
CVE-2023-33183
Some internal paths of the website are disclosed when the SMTP server is unavailable.
MEDIUM 4.3EPSS 0.44%
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- nextcloud/calendar
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/calendar/pull/4938Patch
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2792-2734-hr7jVendor Advisory
- https://github.com/nextcloud/calendar/pull/4938Patch
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2792-2734-hr7jVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.