CVE-2019-15623
Summary
| CVE | CVE-2019-15623 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-04 20:15:00 UTC |
| Updated | 2021-10-29 16:22:00 UTC |
| Description | Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nextcloud | Nextcloud Server | All | All | All | All |
| Application | Nextcloud | Nextcloud Server | All | All | All | All |
| Application | Opensuse | Backports Sle | 15.0 | sp1 | All | All |
| Application | Suse | Package Hub | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] openSUSE-SU-2020:0220-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| HackerOne | MISC | hackerone.com | Exploit, Third Party Advisory |
| advisory – Nextcloud | MISC | nextcloud.com | Third Party Advisory, Vendor Advisory |
| [security-announce] openSUSE-SU-2020:0229-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.