Session Fixation Vulnerability in ownCloud Server
CVE-2021-35948

5.4MEDIUM

Key Information:

Vendor

Owncloud

Status
Vendor
CVE Published:
7 September 2021

What is CVE-2021-35948?

A session fixation vulnerability exists in ownCloud Server versions prior to 10.8.0. This flaw allows attackers to bypass password protection on public links by forcing a targeted user to use a cookie they control. By exploiting this vulnerability, an attacker could gain unauthorized access to sensitive data, undermining the security measures designed to protect user sessions.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.