Lucene search

K
cvelistHackeroneCVELIST:CVE-2019-15623
HistoryFeb 04, 2020 - 7:08 p.m.

CVE-2019-15623

2020-02-0419:08:57
CWE-359
hackerone
www.cve.org

6.3 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.0%

Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it’s domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

CNA Affected

[
  {
    "product": "Nextcloud Server",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "16.0.1"
      }
    ]
  }
]

6.3 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.0%