Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43jc-34rg-43q9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.

ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.

EPSS

Процентиль: 52%
0.00293
Низкий

3.1 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.1
ubuntu
около 10 лет назад

ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.

CVSS3: 3.1
nvd
около 10 лет назад

ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.

CVSS3: 3.1
debian
около 10 лет назад

ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5 ...

EPSS

Процентиль: 52%
0.00293
Низкий

3.1 Low

CVSS3

Дефекты

CWE-200