Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
Link | Tags |
---|---|
https://hackerone.com/reports/508490 | third party advisory exploit |
https://nextcloud.com/security/advisory/?id=NC-SA-2019-016 | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.html | mailing list third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.html | third party advisory vendor advisory |