VulnerabilityModified
CVE-2019-15623
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
MEDIUM 5.3EPSS 1.92%
Does this matter?
Lower severity and a low EPSS score (1.92%). Track it; it rarely justifies an emergency change on its own.
Description
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.92% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-359
- Affected
- nextcloud/nextcloud server · opensuse/backports sle · suse/package hub
- Source
- support@hackerone.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.htmlThird Party Advisory
- https://hackerone.com/reports/508490Exploit, Third Party Advisory
- https://nextcloud.com/security/advisory/?id=NC-SA-2019-016Third Party Advisory, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.htmlThird Party Advisory
- https://hackerone.com/reports/508490Exploit, Third Party Advisory
- https://nextcloud.com/security/advisory/?id=NC-SA-2019-016Third Party Advisory, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.