Access Control Flaw in OwnCloud Server by OwnCloud
CVE-2020-36252

5.7MEDIUM

Key Information:

Vendor

Owncloud

Status
Vendor
CVE Published:
19 February 2021

What is CVE-2020-36252?

An access control vulnerability in OwnCloud Server prior to version 10.3.1 can be exploited by an attacker with at least one outgoing share from a victim. This flaw allows unauthorized access to any file version by sending requests containing predictable ID numbers. This can lead to unintended data exposure and raises concerns about user privacy and data integrity within the platform.

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.