cbcvebase.
CVE-2015-7298
published 2015-10-26

CVE-2015-7298: ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors to be…

PriorityP422medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
0.67%
48.3th percentile
ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which makes it easier for remote attackers to conduct man-in-the-middle (MITM) attacks by leveraging a server using a self-signed certificate. NOTE: this vulnerability exists because of a partial CVE-2015-4456 regression.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianowncloud-client< owncloud-client 2.0.0+dfsg-1 (bookworm)owncloud-client 2.0.0+dfsg-1 (bookworm)
owncloudowncloud_desktop_client<= 2.0.0
qtqt
qtqt

CVSS provenance

nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv2.6LOW
vendor_debian2.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.