PT-2020-9744 · Nextcloud · Nextcloud Talk

Published

2020-02-04

·

Updated

2020-10-09

·

CVE-2019-15620

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Talk version 6.0.3
Description The issue is related to improper access control, which leaks the existence and the name of private conversations when they are linked to another shared item via the projects feature.
Recommendations For Nextcloud Talk version 6.0.3, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15620

Affected Products

Nextcloud Talk