CVE-2024-37316

Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:23

Type Values Removed Values Added
References () https://github.com/nextcloud/calendar/pull/5966 - Patch () https://github.com/nextcloud/calendar/pull/5966 - Patch
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2r7q-vfmv-79qf - Third Party Advisory () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2r7q-vfmv-79qf - Third Party Advisory
References () https://hackerone.com/reports/2457588 - Issue Tracking () https://hackerone.com/reports/2457588 - Issue Tracking

19 Aug 2024, 15:31

Type Values Removed Values Added
References () https://github.com/nextcloud/calendar/pull/5966 - () https://github.com/nextcloud/calendar/pull/5966 - Patch
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2r7q-vfmv-79qf - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2r7q-vfmv-79qf - Third Party Advisory
References () https://hackerone.com/reports/2457588 - () https://hackerone.com/reports/2457588 - Issue Tracking
First Time Nextcloud calendar
Nextcloud
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*

17 Jun 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) Nextcloud Calendar es una aplicación de calendario para Nextcloud. Los usuarios autenticados podrían crear un evento con datos adjuntos manipulados que provoquen una mala redirección para los participantes cuando se haga clic en ellos. Se recomienda actualizar la aplicación Calendario de Nextcloud a 4.6.8 o 4.7.2.

14 Jun 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-14 16:15

Updated : 2024-11-21 09:23


NVD link : CVE-2024-37316

Mitre link : CVE-2024-37316

CVE.ORG link : CVE-2024-37316


JSON object : View

Products Affected

nextcloud

  • calendar
CWE
CWE-241

Improper Handling of Unexpected Data Type

NVD-CWE-noinfo