An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
https://nextcloud.com/security/advisory/?id=NC-SA-2019-014
https://hackerone.com/reports/427835
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.html
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.html