Access Control Flaw in ownCloud by ownCloud GmbH
CVE-2021-29659
6.5MEDIUM
What is CVE-2021-29659?
In ownCloud version 10.7, a vulnerability has been identified that allows incorrect access control, which could lead to remote information disclosure. An attacker can exploit this flaw through a specific bug in the API endpoint, enabling them to enumerate all users with a single request by simply entering three whitespaces. This method not only exposes user data but may also result in excessive load on larger instances, impacting overall system performance.