Events information leaked with shared calendars on recurrence exceptions
Package
Server
(Nextcloud)
Affected versions
>= 27.0.0, >= 28.0.0, >= 29.0.0
Patched versions
27.1.10, 28.0.6, 29.0.1
Server
(Nextcloud Enterprise)
>= 27.0.0, >= 28.0.0, >= 29.0.0
27.1.10, 28.0.6, 29.0.1
Impact
Private shared calendar events' recurrence exceptions can be read by sharees.
Patches
It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1
It is recommended that the Nextcloud Enterprise Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1
Workarounds
References
For more information
If you have any questions or comments about this advisory: