CVE-2019-15623: Nextcloud Server

Medium severity, CVSS 5.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

Affected products

  • Nextcloud Nextcloud Server: before 14.0.13 (fixed in 14.0.13); from 15.0.0, before 15.0.9 (fixed in 15.0.9); from 16.0.0, before 16.0.2 (fixed in 16.0.2)
  • Opensuse Backports Sle: version 15.0 only
  • Suse Package Hub: affected versions not specified

Published 2020-02-04. Last modified 2026-06-17.