CVE-2022-43679
- EPSS 0.18%
- Veröffentlicht 10.11.2022 21:15:11
- Zuletzt bearbeitet 01.05.2025 14:15:30
The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages.
CVE-2022-31649
- EPSS 0.39%
- Veröffentlicht 09.06.2022 04:15:11
- Zuletzt bearbeitet 21.11.2024 07:05:02
ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
CVE-2021-35946
- EPSS 0.31%
- Veröffentlicht 07.09.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:48
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.
CVE-2021-35948
- EPSS 0.17%
- Veröffentlicht 07.09.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:48
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.
CVE-2021-35947
- EPSS 0.26%
- Veröffentlicht 07.09.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:12:48
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.
CVE-2021-35949
- EPSS 0.18%
- Veröffentlicht 07.09.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:12:48
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.
CVE-2020-10252
- EPSS 0.58%
- Veröffentlicht 19.02.2021 07:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:04
An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attac...
CVE-2020-10254
- EPSS 0.32%
- Veröffentlicht 19.02.2021 07:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:04
An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.
CVE-2020-36251
- EPSS 0.21%
- Veröffentlicht 19.02.2021 07:15:13
- Zuletzt bearbeitet 21.11.2024 05:29:09
ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove everyone else's access to that share.
CVE-2020-28644
- EPSS 0.15%
- Veröffentlicht 09.02.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:23:05
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.