CVE Vulnerabilities

CVE-2019-15623

Published: Feb 04, 2020 | Modified: Oct 29, 2021
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send its domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

Affected Software

Name Vendor Start Version End Version
Nextcloud_server Nextcloud * 14.0.13 (excluding)
Nextcloud_server Nextcloud 15.0.0 (including) 15.0.9 (excluding)
Nextcloud_server Nextcloud 16.0.0 (including) 16.0.2 (excluding)

References