CVE-2019-15623: Medium severity nextcloud server vulnerability
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15623?
CVE-2019-15623 is a vulnerability in Nextcloud Server 16.0.1 that exposes private information by sending the server's domain and user IDs to the Nextcloud Lookup Server.
How does the vulnerability in Nextcloud Server 16.0.1 work?
The vulnerability in Nextcloud Server 16.0.1 causes the server to send its domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
What is the severity of CVE-2019-15623?
The severity rating of CVE-2019-15623 is medium, with a severity value of 5.3.
Which software versions are affected by CVE-2019-15623?
Nextcloud Server versions 14.0.13, 15.0.0 to 15.0.9, and 16.0.0 to 16.0.2 are affected by CVE-2019-15623.
How can I fix the vulnerability in Nextcloud Server 16.0.1?
To fix the vulnerability, you should upgrade Nextcloud Server to a version that is not affected by CVE-2019-15623.