CVE-2024-37887

Source
https://cve.org/CVERecord?id=CVE-2024-37887
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37887.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-37887
Aliases
  • GHSA-h4xv-cjpm-j595
Published
2024-06-14T15:48:11.867Z
Modified
2026-02-07T21:06:04.316930Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Nextcloud Server's events information leaked with shared calendars on recurrence exceptions
Details

Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enterprise Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37887.json"
}
References

Affected packages

Git / github.com/nextcloud/server

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/server
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37887.json"