Information disclosure in Nextcloud Server - CVE-2019-5449
Published: July 30, 2019 / Updated: July 17, 2020
Vulnerability identifier: #VU30977
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5449
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to gain access to sensitive information.
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
Affected software
Nextcloud Server
How to mitigate CVE-2019-5449
Install update from vendor's website.
Nextcloud Server - update to 15.0.1