ZeroHour

CVE-2019-15623

PoC
CVSS 3.1
5.3 medium
EPSS
2%p79
Published
()
Modified
Description

Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

Vendors
nextcloudopensusesuse
Products
nextcloud server, backports sle, package hub
Weakness
CWE-359
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.