Insecure OpenID Implementation in ownCloud Server by ownCloud
CVE-2014-2048

9.8CRITICAL

Key Information:

Vendor

Owncloud

Status
Vendor
CVE Published:
26 March 2018

What is CVE-2014-2048?

The ownCloud Server versions prior to 5.0.15 are vulnerable to a security flaw that allows remote attackers to exploit an insecure implementation of OpenID within the user_openid application. This vulnerability can potentially enable unauthorized access to sensitive user data, putting users' information at serious risk. It is crucial for users to ensure they are utilizing an updated version of the ownCloud Server to mitigate this risk.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.