Impact
The Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely random generated.
Patches
It is recommended that the Calendar app is upgraded to 6.0.3
Workarounds
References
For more information
If you have any questions or comments about this advisory:
Impact
The Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely random generated.
Patches
It is recommended that the Calendar app is upgraded to 6.0.3
Workarounds
References
For more information
If you have any questions or comments about this advisory: