Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-5954

Опубликовано: 21 окт. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4

Описание

The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [empty package]]
precise

not-affected

empty package
trusty

not-affected

empty package
trusty/esm

DNE

trusty was not-affected [empty package]
upstream

released

7.0.6+dfsg-1
vivid

DNE

Показывать по

EPSS

Процентиль: 35%
0.00143
Низкий

4 Medium

CVSS2

Связанные уязвимости

nvd
больше 10 лет назад

The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder.

debian
больше 10 лет назад

The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7 ...

github
больше 3 лет назад

The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder.

fstec
больше 10 лет назад

Уязвимость веб-приложения для синхронизации данных ownCloud, позволяющая нарушителю обойти существующие ограничения доступа и получить доступ к файлам пользователей

EPSS

Процентиль: 35%
0.00143
Низкий

4 Medium

CVSS2