CVE-2015-5954Owncloud vulnerability

6 documents4 sources
Severity
4.0MEDIUMNVD
EPSS
0.1%
top 65.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 21
Latest updateMay 17

Description

The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

NVDowncloud/owncloud_server11 versions+10

🔴Vulnerability Details

2
GHSA
GHSA-9hxw-x8cc-hmwq: The virtual filesystem in ownCloud Server before 62022-05-17
CVEList
CVE-2015-5954: The virtual filesystem in ownCloud Server before 62015-10-21

💬Community

3
Bugzilla
CVE-2015-4717 CVE-2015-7699 CVE-2015-5954 CVE-2015-5953 CVE-2015-4718 owncloud: Multiple vulnerabilities fixed [fedora-all]2015-10-19
Bugzilla
CVE-2015-4717 CVE-2015-4718 CVE-2015-5953 CVE-2015-5954 CVE-2015-7699 CVE-2015-4716 owncloud: Multiple vulnerabilities fixed2015-10-19
Bugzilla
CVE-2015-4717 CVE-2015-7699 CVE-2015-5954 CVE-2015-5953 CVE-2015-4718 owncloud: Multiple vulnerabilities fixed [epel-all]2015-10-19
CVE-2015-5954 — Owncloud vulnerability | cvebase