Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Section1

#55123of 56,326
4Total CVSS
Vulnerabilities · 1
PT-2024-4380
4.0
2024-06-14
Nextcloud · Nextcloud Server · CVE-2024-37887
**Name of the Vulnerable Software and Affected Versions** Nextcloud Server versions prior to 27.1.10 Nextcloud Server versions prior to 28.0.6 Nextcloud Server versions prior to 29.0.1 Nextcloud Enterprise Server versions prior to 27.1.10 Nextcloud Enterprise Server versions prior to 28.0.6 Nextcloud Enterprise Server versions prior to 29.0.1 **Description** The issue is related to incorrect access control in the Calendar component of Nextcloud Server, allowing sharees to read private shared calendar events' recurrence exceptions. This can enable a remote attacker to access confidential information. **Recommendations** For Nextcloud Server versions prior to 27.1.10, upgrade to version 27.1.10 or later. For Nextcloud Server versions prior to 28.0.6, upgrade to version 28.0.6 or later. For Nextcloud Server versions prior to 29.0.1, upgrade to version 29.0.1 or later. For Nextcloud Enterprise Server versions prior to 27.1.10, upgrade to version 27.1.10 or later. For Nextcloud Enterprise Server versions prior to 28.0.6, upgrade to version 28.0.6 or later. For Nextcloud Enterprise Server versions prior to 29.0.1, upgrade to version 29.0.1 or later.