CVE-2019-5449
Dashboard / Vulnerabilities / CVE-2019-5449
CVE-2019-5449
Published: 30 Jul 2019Last Modified: 7 Aug 2026
Summary:
Details: A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
References: https://hackerone.com/reports/476615
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v15.0.1RC1
v15.0.1RC2
v15.0.0
v15.0.0RC3
v15.0.0RC2
v15.0.0RC1
v15.0.0beta2
v15.0.0beta1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
