Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
{ "cpe": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*", "extracted_events": [ { "introduced": "10.0.0" }, { "fixed": "10.0.4" }, { "introduced": "11.0.0" }, { "fixed": "11.0.2" } ], "source": "CPE_RANGE" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-0895.json"