You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Learn more on MITRE.
Impact
The calendar app allowed blindly booking appointments with a squential ID without known the appointment token.
Patches
It is recommended that Nextcloud Calendar is upgraded to 4.7.19, 5.5.6 or 6.0.1.
Workarounds
References
For more information
If you have any questions or comments about this advisory: