4

CVE-2015-5954

The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder.

Data is provided by the National Vulnerability Database (NVD)
OwncloudOwncloud Version <= 6.0.8
OwncloudOwncloud Server Version7.0.0
OwncloudOwncloud Server Version7.0.1
OwncloudOwncloud Server Version7.0.2
OwncloudOwncloud Server Version7.0.3
OwncloudOwncloud Server Version7.0.4
OwncloudOwncloud Server Version7.0.5
OwncloudOwncloud Server Version7.0.6
OwncloudOwncloud Server Version8.0.0
OwncloudOwncloud Server Version8.0.2
OwncloudOwncloud Server Version8.0.3
OwncloudOwncloud Server Version8.0.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.31
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N