Anyone who has view rights on the Calendar.JSONService page, including guest users can exploit this vulnerability by accessing database info, with the exception of passwords.
Remove the Calendar.JSONService page. This will however break some functionalities.
Jira issue:
If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-200"
],
"github_reviewed": true,
"github_reviewed_at": "2026-01-09T18:35:57Z",
"nvd_published_at": "2026-01-10T04:16:01Z",
"severity": "MODERATE"
}