CVE-2020-10254Improper Authentication in Owncloud

Severity
5.9MEDIUMNVD
EPSS
0.3%
top 45.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19
Latest updateMay 24

Description

An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages1 packages

NVDowncloud/owncloud< 10.4.0

🔴Vulnerability Details

2
GHSA
GHSA-p22f-p3r6-57j7: An issue was discovered in ownCloud before 102022-05-24
CVEList
CVE-2020-10254: An issue was discovered in ownCloud before 102021-02-19
CVE-2020-10254 — Improper Authentication in Owncloud | cvebase