Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://hackerone.com/reports/203594 | vdb entry third party advisory |
https://nextcloud.com/security/advisory/?id=nc-sa-2017-012 | vendor advisory |