Owncloud

Owncloud

116 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 10.11.2022 21:15:11
  • Zuletzt bearbeitet 01.05.2025 14:15:30

The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages.

  • EPSS 0.39%
  • Veröffentlicht 09.06.2022 04:15:11
  • Zuletzt bearbeitet 21.11.2024 07:05:02

ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.

  • EPSS 0.31%
  • Veröffentlicht 07.09.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:48

A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.

  • EPSS 0.17%
  • Veröffentlicht 07.09.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:48

Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.

  • EPSS 0.26%
  • Veröffentlicht 07.09.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:12:48

The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.

  • EPSS 0.18%
  • Veröffentlicht 07.09.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:12:48

The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.

Exploit
  • EPSS 0.58%
  • Veröffentlicht 19.02.2021 07:15:13
  • Zuletzt bearbeitet 21.11.2024 04:55:04

An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attac...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 19.02.2021 07:15:13
  • Zuletzt bearbeitet 21.11.2024 04:55:04

An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.

  • EPSS 0.21%
  • Veröffentlicht 19.02.2021 07:15:13
  • Zuletzt bearbeitet 21.11.2024 05:29:09

ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove everyone else's access to that share.

  • EPSS 0.15%
  • Veröffentlicht 09.02.2021 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:23:05

The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.