File Storage Vulnerability in ownCloud Affecting Unauthorized Access to Uploaded Files
CVE-2020-16144

5.7MEDIUM

Key Information:

Vendor

Owncloud

Vendor
CVE Published:
9 February 2021

What is CVE-2020-16144?

A security flaw exists in the files_antivirus component of ownCloud versions prior to 0.15.2. When users create public links enabling anonymous file uploads to S3 object storage, uploaded files containing viruses may be detected by the antivirus application but cannot be deleted due to insufficient permissions. This vulnerability poses a significant risk as it allows the potential for malicious files to remain on the system, leading to possible exploitation.

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.