CVE-2023-33183
Summary
| CVE | CVE-2023-33183 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-30 06:16:00 UTC |
| Updated | 2023-06-05 18:11:00 UTC |
| Description | Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3 |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Error in calendar when booking an appointment reveals the full path of the website · Advisory · nextcloud/security-advisories · GitHub | MISC | github.com | |
| Refine exception handling for booking controller by miaulalala · Pull Request #4938 · nextcloud/calendar · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.