CVE-2016-1501Sensitive Information Exposure in Owncloud

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 58.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 8
Latest updateMay 17

Description

ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDowncloud/owncloud_server8.1.0, 8.1.1, 8.1.3+2

🔴Vulnerability Details

2
GHSA
GHSA-g66g-4wvr-3crm: ownCloud Server before 82022-05-17
CVEList
CVE-2016-1501: ownCloud Server before 82016-01-08

💬Community

4
Bugzilla
CVE-2016-1501 owncloud: full installation path disclosure through error message [fedora-all]2016-01-11
Bugzilla
CVE-2016-1501 owncloud: full installation path disclosure through error message [epel-6]2016-01-11
Bugzilla
CVE-2016-1501 owncloud: full installation path disclosure through error message [epel-7]2016-01-11
Bugzilla
CVE-2016-1501 owncloud: full installation path disclosure through error message2016-01-11
CVE-2016-1501 — Sensitive Information Exposure | cvebase