CVE-2020-36252Use of Insufficiently Random Values in Server

Severity
5.7MEDIUMNVD
CNA6.8
EPSS
0.1%
top 75.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19
Latest updateMay 24

Description

ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.1 | Impact: 3.6

Affected Packages1 packages

NVDowncloud/owncloud_server10.0.910.3.1

🔴Vulnerability Details

2
GHSA
GHSA-gc7p-gg9x-38qq: ownCloud Server 102022-05-24
CVEList
CVE-2020-36252: ownCloud Server 102021-02-19
CVE-2020-36252 — Use of Insufficiently Random Values | cvebase