CVE-2024-37316

Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*

History

19 Aug 2024, 15:31

Type Values Removed Values Added
First Time Nextcloud calendar
Nextcloud
CPE cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*
References () https://github.com/nextcloud/calendar/pull/5966 - () https://github.com/nextcloud/calendar/pull/5966 - Patch
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2r7q-vfmv-79qf - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2r7q-vfmv-79qf - Third Party Advisory
References () https://hackerone.com/reports/2457588 - () https://hackerone.com/reports/2457588 - Issue Tracking
CWE NVD-CWE-noinfo

17 Jun 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) Nextcloud Calendar es una aplicación de calendario para Nextcloud. Los usuarios autenticados podrían crear un evento con datos adjuntos manipulados que provoquen una mala redirección para los participantes cuando se haga clic en ellos. Se recomienda actualizar la aplicación Calendario de Nextcloud a 4.6.8 o 4.7.2.

14 Jun 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-14 16:15

Updated : 2024-08-19 15:31


NVD link : CVE-2024-37316

Mitre link : CVE-2024-37316

CVE.ORG link : CVE-2024-37316


JSON object : View

Products Affected

nextcloud

  • calendar
CWE
NVD-CWE-noinfo CWE-241

Improper Handling of Unexpected Data Type