Insecure OpenID Implementation in ownCloud Server by ownCloud
CVE-2014-2048
9.8CRITICAL
What is CVE-2014-2048?
The ownCloud Server versions prior to 5.0.15 are vulnerable to a security flaw that allows remote attackers to exploit an insecure implementation of OpenID within the user_openid application. This vulnerability can potentially enable unauthorized access to sensitive user data, putting users' information at serious risk. It is crucial for users to ensure they are utilizing an updated version of the ownCloud Server to mitigate this risk.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
