CVE-2014-3835Owncloud vulnerability

CWE-2643 documents3 sources
Severity
5.5MEDIUMNVD
EPSS
0.3%
top 46.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 4
Latest updateMay 17

Description

ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not check permissions to the files_external application, which allows remote authenticated users to add external storage via unspecified vectors.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 8.0 | Impact: 4.9

Affected Packages2 packages

NVDowncloud/owncloud_server18 versions+17
NVDowncloud/owncloud5.0.15

🔴Vulnerability Details

2
GHSA
GHSA-22vm-23gq-9vc9: ownCloud Server before 52022-05-17
CVEList
CVE-2014-3835: ownCloud Server before 52014-06-04
CVE-2014-3835 — Owncloud vulnerability | cvebase