File-Type Restriction Bypass in ownCloud Server by ownCloud
CVE-2020-36249

7.5HIGH

Key Information:

Vendor

Owncloud

Vendor
CVE Published:
19 February 2021

What is CVE-2020-36249?

A vulnerability in the File Firewall feature of ownCloud Server prior to version 2.8.0 allows unauthorized users to bypass file-type restrictions set for public shares. This flaw may enable attackers to upload malicious files, posing a risk to sensitive data stored on the server and compromising overall system security. Users are urged to upgrade to the latest version to mitigate this issue effectively.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.