Security Advisory

CVE-2017-0894

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-05-08 20:00:00
Last updated 2024-08-05 13:18:06
Assigner hackerone
State PUBLISHED

Description

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.