Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-16144

Опубликовано: 09 фев. 2021
Источник: nvd
CVSS3: 5.7
CVSS2: 3.5
EPSS Низкий

Описание

When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:owncloud:files_antivirus:*:*:*:*:*:*:*:*
Версия до 0.15.2 (исключая)

EPSS

Процентиль: 40%
0.00182
Низкий

5.7 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 5.7
ubuntu
почти 5 лет назад

When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud.

CVSS3: 5.7
debian
почти 5 лет назад

When using an object storage like S3 as the file store, when a user cr ...

github
больше 3 лет назад

When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud.

EPSS

Процентиль: 40%
0.00182
Низкий

5.7 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-276