CVE-2020-10252Server-Side Request Forgery in Owncloud

Severity
8.3HIGHNVD
EPSS
0.6%
top 30.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19
Latest updateMay 24

Description

An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:HExploitability: 2.8 | Impact: 5.5

Affected Packages1 packages

NVDowncloud/owncloud< 10.4.0

🔴Vulnerability Details

2
GHSA
GHSA-jjpp-cjc4-jw4h: An issue was discovered in ownCloud before 102022-05-24
CVEList
CVE-2020-10252: An issue was discovered in ownCloud before 102021-02-19
CVE-2020-10252 — Server-Side Request Forgery | cvebase