Back to search
CVE-2019-15623
Published: Feb 4, 2020
Modified: Aug 5, 2024
PUBLISHED
Description
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
| Vendor | Product | Versions |
|---|---|---|
n/a | Nextcloud Server | affected 16.0.1 |
Weaknesses (CWE)
References
https://hackerone.com/reports/508490
x_refsource_MISC
https://nextcloud.com/security/advisory/?id=NC-SA-2019-016
x_refsource_MISC
openSUSE-SU-2020:0220
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:0229
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now