Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c99-9fv7-72hj

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

EPSS

Процентиль: 76%
0.00978
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-285
CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
около 8 лет назад

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

CVSS3: 4.3
debian
около 8 лет назад

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid sh ...

EPSS

Процентиль: 76%
0.00978
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-285
CWE-863