{"api_version":"1","generated_at":"2026-07-23T13:21:36+00:00","cve":"CVE-2023-33183","urls":{"html":"https://cve.report/CVE-2023-33183","api":"https://cve.report/api/cve/CVE-2023-33183.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-33183","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-33183"},"summary":{"title":"CVE-2023-33183","description":"Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2023-05-30 06:16:00","updated_at":"2023-06-05 18:11:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2792-2734-hr7j","name":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2792-2734-hr7j","refsource":"MISC","tags":[],"title":"Error in calendar when booking an appointment reveals the full path of the website · Advisory · nextcloud/security-advisories · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/nextcloud/calendar/pull/4938","name":"https://github.com/nextcloud/calendar/pull/4938","refsource":"MISC","tags":[],"title":"Refine exception handling for booking controller by miaulalala · Pull Request #4938 · nextcloud/calendar · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-33183","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33183","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"33183","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nextcloud","cpe5":"calendar","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-33183","ASSIGNER":"security-advisories@github.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3\n\n"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-285: Improper Authorization","cweId":"CWE-285"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"nextcloud","product":{"product_data":[{"product_name":"security-advisories","version":{"version_data":[{"version_affected":"=","version_value":"< 3.5.5"},{"version_affected":"=","version_value":"< 4.2.3"}]}}]}}]}},"references":{"reference_data":[{"url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2792-2734-hr7j","refsource":"MISC","name":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2792-2734-hr7j"},{"url":"https://github.com/nextcloud/calendar/pull/4938","refsource":"MISC","name":"https://github.com/nextcloud/calendar/pull/4938"}]},"source":{"advisory":"GHSA-2792-2734-hr7j","discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":2.6,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","version":"3.1"}]}},"nvd":{"publishedDate":"2023-05-30 06:16:00","lastModifiedDate":"2023-06-05 18:11:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.2.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*","versionEndExcluding":"3.5.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}