An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.Referenceshttps://hackerone.com/reports/427835https://nextcloud.com/security/advisory/?id=NC-SA-2019-014http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.html