CVE-2017-0895

LOW

Nextcloud Server <10.0.4,11.0.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://hackerone.com/reports/203594

Scores

CVSS v3 3.5
EPSS 0.0013
EPSS Percentile 31.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-285
Status published
Products (2)
Nextcloud/Nextcloud Server before 10.0.4 and 11.0.2
nextcloud/nextcloud_server 10.0.0 - 10.0.4
Published May 08, 2017
Tracked Since Feb 18, 2026