Information disclosure in Nextcloud Server - CVE-2019-5449

 

Information disclosure in Nextcloud Server - CVE-2019-5449

Published: July 30, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30977
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5449
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.


Affected software

Nextcloud Server

How to mitigate CVE-2019-5449

Install update from vendor's website.

Nextcloud Server - update to 15.0.1

External References

Related Security Bulletins