Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Nextcloud Calendar app used predictable proposal participant tokens
Vulnerability Description
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely random generated. This vulnerability is fixed in 6.0.3.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
使用不充分的随机数
Vulnerability Title
Nextcloud Calendar 安全特征问题漏洞
Vulnerability Description
Nextcloud Calendar是Nextcloud开源的一个日历应用程序。 Nextcloud Calendar 6.0.3之前版本存在安全特征问题漏洞,该漏洞源于会议提案参与者令牌生成方式不安全,可能导致令牌被计算。
CVSS Information
N/A
Vulnerability Type
N/A