{"id":"CVE-2019-15620","details":"Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.","modified":"2026-04-11T14:11:00.911291Z","published":"2020-02-04T20:15:12.447Z","references":[{"type":"ADVISORY","url":"https://nextcloud.com/security/advisory/?id=NC-SA-2020-011"},{"type":"REPORT","url":"https://hackerone.com/reports/662218"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/talk-android","events":[{"introduced":"0"},{"fixed":"96de8ceb935e5005e95b1d7409075ef74c2fb528"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"6.0.4"}]}}],"versions":["v0.1.0","v0.1.1","v0.1.2","v0.2.0","v1.0","v1.0.1","v1.0.10","v1.0.11","v1.0.12","v1.0.13","v1.0.14","v1.0.2","v1.0.3","v1.0.4","v1.0.5","v1.0.6","v1.0.7","v1.0.8","v1.0.9","v1.1.0","v1.1.0beta1","v1.1.0beta2","v1.1.0beta3","v1.1.0beta4","v1.1.1","v1.2.0beta1","v1.2.0beta2","v1.2.0beta3","v2.0.0","v2.0.0beta4","v2.0.0beta5","v2.1.0","v2.1.0beta1","v2.1.0beta2","v2.1.0beta3","v2.1.0beta4","v2.1.0beta5","v3.0.0","v3.0.0beta1","v3.0.0beta10","v3.0.0beta3","v3.0.0beta4","v3.0.0beta5","v3.0.0beta6","v3.0.0beta7","v3.0.0beta8","v3.0.1","v3.1.0","v3.1.0beta1","v3.1.0beta2","v3.1.0beta3","v3.1.0beta4","v3.1.0beta5","v3.1.0beta6","v3.2.0beta1","v3.2.0beta2","v3.2.0beta3","v3.2.0beta4","v3.2.0beta5","v3.3.0beta1","v3.3.0beta2","v3.3.0beta3","v6.0.0","v6.0.0beta1","v6.0.0beta2","v6.0.0beta3","v6.0.0beta4","v6.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15620.json","vanir_signatures":[{"signature_type":"Function","target":{"function":"joinRoomWithRoomTokenAndSession","file":"app/src/main/java/com/nextcloud/talk/webrtc/MagicWebSocketInstance.java"},"source":"https://github.com/nextcloud/talk-android/commit/96de8ceb935e5005e95b1d7409075ef74c2fb528","id":"CVE-2019-15620-1597a010","digest":{"function_hash":"298371678596391023087716559718708850582","length":632},"deprecated":false,"signature_version":"v1"},{"signature_type":"Line","target":{"file":"app/src/main/java/com/nextcloud/talk/webrtc/MagicWebSocketInstance.java"},"source":"https://github.com/nextcloud/talk-android/commit/96de8ceb935e5005e95b1d7409075ef74c2fb528","id":"CVE-2019-15620-b02cd2a7","digest":{"threshold":0.9,"line_hashes":["197700212335015500041838697513846064728","86308677864318993497408718807494758661","110614973695056361178640246290610247119","257560811681439136534511970816853692402","240712112128381599083847548699798567078","101553157878789736064076680940630740942","299291355225054030123352048214213677835","119599119503376397888828285134289858133","155934923995627190679106257561340007070","247395927670163166242791463578940004561","312277393331497870185067007153234610936","252722396108618984351491563116782303778","62810169808014941250870117488332285042","133154326832986357381609166514415773375","197634367623488963880911111823819155085","261176701202609996978472474122063575686","323108818648551323917903866579290223656","40745026477516682411085469881153256086","25940077064843905954910657866120618110","190370760082845276864705417331985393746","117393689574739830005806184478255298581","165630151192618464192705554388138183120","152573999556475080784009614742589607865","121254117625421490349136479045968546655","98666307130977921840354563868882787241","12626809874493150368863702282156572469","102143505945976651087241459943848278243"]},"deprecated":false,"signature_version":"v1"}],"vanir_signatures_modified":"2026-04-11T14:11:00Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"}]}