Meta tags:
description= This page hosts ownCloud security policies and information with regards to reporting security flaws.;
Headings (most frequently used words):
in, owncloud, security, the, to, of, bypass, app, api, validation, share, public, can, server, user, disclosure, and, for, on, request, forgery, url, permissions, android, through, lock, file, if, sharing, files, improper, access, authentication, using, links, password, information, desktop, client, your, community, get, what, cross, site, via, side, federated, pre, signed, urls, sensitive, path, settings, updates, internal, missing, ssrf, doesn, shared, folders, code, admin, injection, xss, page, bypassing, oc, sa, 2020, delete, link, be, system, group, versions, as, update, communications, about, process, product, apps, us, is, how, do, my, should, or, assistance, issues, an, advisories, notice, impact, cve, 2026, 33634, build, infrastructure, advisory, credential, theft, incidents, diagnostics, manipulation, when, email, insecure, direct, object, reference, external, storage, control, svg, preview, generation, avatar, mechanism, profile, metadata, biometric, denial, service, comments, subdomain, webdav, credentials, configuration, containerized, deployments, edit, causes, misbehaviour, sqlinjection, filecontentprovider, kt, insufficient, spoofing, reset, mail, ui, responses, allowed, rce, user_ldap, recipient, increase, shareinfo, verify, drop, session, fixation, full, username, upload, malicious, publicly, arbitrary, execution, authenticated, account, enumeration, dialog, dll, ocs, leading, reflected, login, forgot, functionallity, pattern, passcode, fingerprint, 003, firewall, 002, files_antivirus, virus, uploaded, bypassed, by, changing, date, deleting, received, whole, image, previews, add, functionality, all, soon, he, has, one, with, attacker, possibility, extend, error, tokens, calendars, disclosed, normal, somehow, make, local, application, specific, pin, secure, platform, faqs, reasons, why, content, require, hardened, virtual, appliance, want, learn, more, capabilities, securing, hall, fame, responsible, guidelines, out, scope, supported, third, party, complete, checklist, achieve, hipaa, compliance, products, solutions, resources, partners, policies, started, company, help, legal, follow, issue, affecting, know, 10, installation, affected, immediate, actions, take, where, find, instructions, updating, patching, who, contact, encounter, during, will, there, further, this, other, subscription, order, currently, run, version, install, start, online, download, mobile,
Text of the page (most frequently used words):
cwe (124), cvss (102), the (94), owncloud (73), cve (58), more (56), read (53), risk (50), description (49), base (48), score (48), name (43), vector (42), #improper (36), for (35), server (32), and (29), security (29), medium (21), access (21), low (21), 2024 (20), 2020 (19), 2021 (19), our (18), app (18), validation (17), share (15), information (14), file (14), versions (14), attacker (14), may (14), platform (13), date (13), control (13), public (13), your (12), with (12), request (11), api (11), allow (11), 2023 (11), contact (10), bypass (10), forgery (10), you (10), community (9), desktop (9), android (9), sharing (9), user (9), can (9), 284 (9), affected (9), 2022 (9), download (8), level (8), was (8), aug (8), input (8), authenticated (8), vulnerability (8), are (8), vulnerabilities (8), team (8), 2026 (7), code (7), get (7), apps (7), from (7), authentication (7), client (7), disclosure (7), permissions (7), sensitive (7), could (7), url (7), please (7), com (7), service (6), marketplace (6), about (6), online (6), apr (6), injection (6), 2017 (6), report (6), page (6), cross (6), site (6), using (6), feb (6), when (6), storage (6), not (6), files (6), update (6), side (6), sep (6), will (6), version (6), subscription (6), system (5), support (5), customers (5), mobile (5), secure (5), issues (5), that (5), process (5), malicious (5), through (5), generation (5), has (5), possible (5), lock (5), settings (5), path (5), links (5), mar (5), this (5), any (5), should (5), microsoft (5), source (4), solutions (4), product (4), 2016 (4), privilege (4), neutralization (4), high (4), use (4), ssrf (4), external (4), jun (4), handling (4), object (4), upload (4), csrf (4), federated (4), insecure (4), critical (4), party (4), learn (4), release (4), products (4), available (4), partner (4), search (3), portal (3), partners (3), features (3), why (3), collaboration (3), clients (3), application (3), specific (3), local (3), attack (3), management (3), delete (3), exposure (3), error (3), during (3), extend (3), received (3), ocs (3), all (3), preview (3), image (3), password (3), via (3), group (3), configuration (3), physical (3), device (3), check (3), insufficient (3), special (3), elements (3), users (3), certain (3), which (3), dec (3), missing (3), were (3), unauthorized (3), command (3), but (3), session (3), only (3), library (3), updates (3), some (3), resources (3), third (3), nov (3), urls (3), direct (3), reference (3), impact (3), responsible (3), following (3), program (3), guidelines (3), hall (3), fame (3), issue (3), securing (3), documentation (3), open (3), content (3), assistance (3), run (3), what (3), upgrade (3), office (3), follow (2), legal (2), demo (2), training (2), faqs (2), customer (2), docs (2), guides (2), help (2), forum (2), beta (2), testing (2), contribute (2), blogs (2), press (2), career (2), events (2), company (2), compare (2), pricing (2), overview (2), self (2), start (2), started (2), productivity (2), next (2), software (2), hosted (2), ready (2), install (2), know (2), within (2), setting (2), pin (2), 114 (2), 269 (2), hackerone (2), normal (2), make (2), admin (2), shared (2), folders (2), caused (2), web (2), scripting (2), xss (2), 2019 (2), permission (2), jul (2), internal (2), incorrect (2), soon (2), functionality (2), link (2), recipient (2), remove (2), deleting (2), given (2), allowed (2), like (2), doesn (2), incomplete (2), bypassing (2), login (2), properly (2), leading (2), 352 (2), requests (2), 200 (2), actor (2), dialog (2), enumeration (2), used (2), administration (2), execution (2), publicly (2), parameters (2), username (2), fixation (2), reset (2), after (2), action (2), protection (2), drop (2), 918 (2), user_ldap (2), resource (2), achieve (2), there (2), known (2), have (2), updated (2), responses (2), due (2), sql (2), where (2), graphapi (2), webdav (2), pre (2), signed (2), crafted (2), redirect (2), comments (2), biometric (2), profile (2), metadata (2), avatar (2), mechanism (2), svg (2), diagnostics (2), hudson (2), rock (2), identified (2), credential (2), theft (2), incidents (2), affecting (2), organizations (2), including (2), trivy (2), 33634 (2), infrastructure (2), compliance (2), also (2), these (2), take (2), actions (2), supported (2), bugs (2), network (2), out (2), scope (2), made (2), time (2), confirm (2), determine (2), fix (2), thank (2), include (2), least (2), who (2), tips (2), communications (2), how (2), provide (2), detailed (2), www (2), services (2), patch (2), instructions (2), find (2), instances (2), infinite (2), scale (2), policies (2), kiteworks (2), integrations (2), copyright, gmbh, english, imprint, privacy, whistleblowing, licensing, trademark, packages, chatroom, sustainability, recognition, awards, quote, changelog, industry, editions, enterprise, trial, bring, game, ios, stores, solution, securely, germany, glimpse, backbone, boost, enable, organization, 592, does, vunerable, 166581, logged, somehow, directory, listing, 548, logical, valid, tokens, calendars, disclosed, subfolder, additional, exists, because, possibility, 648, privileged, apis, one, force, add, previews, 385, whole, faulty, timestamp, bypassed, changing, 280, privileges, store, creates, files_antivirus, virus, uploaded, 791, filtering, folder, rights, firewall, 002, 312, cleartext, creating, pattern, passcode, fingerprint, 003, sanitizing, exception, reflected, forgot, functionallity, names, deleted, higher, systems, token, checked, cookie, against, released, loading, development, plugins, directories, they, present, dll, 29659, implements, mitigation, prevent, account, 33827, arbitrary, 459, cleanup, 33828, detected, 209, message, containing, 35947, appending, characters, query, full, 384, 35948, cookies, authenticating, core, 424, alternate, 35949, circumvented, shareinfo, verify, 266, assignment, 35946, receiver, granted, receivers, increase, 40537, identifiers, 44537, remote, rce, 25338, 25339, wich, 2018, 25032, even, though, includes, zlib, preventive, measure, 212, removal, before, transfer, 31649, few, 923, restriction, communication, channel, intended, endpoints, 43679, docker, contained, oct, spoofing, mail, traversal, 24804, sanitation, write, 23948, exported, sqlinjection, filecontentprovider, 440, expected, behavior, violation, changes, propagated, child, taken, edit, causes, misbehaviour, relies, provides, credentials, containerized, deployments, 665, initialization, modify, without, victim, oauth2, able, pass, specially, bypasses, subdomain, 26320, plugin, denial, 26321, gain, 26322, 26325, 26326, 37011, 639, 37010, 37012, unauthenticated, 235, extra, 37009, notification, manipulation, email, 42014, combination, regarding, january, threat, intelligence, various, platforms, jan, advisory, summary, march, supply, chain, compromised, aqua, scanner, worldwide, their, pipelines, among, those, notice, build, advisories, complete, checklist, hipaa, applications, reported, attempt, 3rd, maintainer, then, proper, ddos, usually, types, publish, related, until, announcement, reasonable, response, detail, applies, test, own, kindly, comply, researching, reporting, member, its, develop, applied, master, branch, tested, packaged, announced, finally, added, entire, reproduction, steps, discovered, three, things, yeswehack, people, helped, servers, owners, section, best, practices, advanced, cloud, set, market, want, capabilities, reasons, require, hardened, virtual, appliance, order, currently, each, notes, well, later, general, continue, visit, future, further, other, immediately, prepared, prompt, resolve, complications, part, encounter, dedicated, assist, them, doc, updating, patching, latest, 49103, 49104, respective, getphpinfo, php, 49105, apply, downloads, immediate, below, current, necessary, don, aren, subject, managed, installation, several, data, integrity, rss, close, blog, github, conduct, ospo, become, project, dna, ftp, drive, gdpr, fileshare, sync, digital, workspace, cases, defense, space, chemicals, pharma, education, healthcare, life, sciences, law, automotive, manufacturing, sector, industries, onlyoffice, collabora, wnd, outlook, teams, 365, now, live,
Text of the page (random words):
hen take proper actions complete checklist to achieve hipaa compliance learn more security advisories security notice impact of cve 2026 33634 on owncloud build infrastructure mar 28 2026 summary on march 19 2026 a critical supply chain attack compromised aqua security s trivy vulnerability scanner cve 2026 33634 cvss 9 4 this attack affected organizations worldwide that use trivy in their ci cd pipelines owncloud was among those affected the read more security advisory credential theft incidents jan 7 2026 information for owncloud users regarding the hudson rock report overview a january 2026 threat intelligence report by hudson rock identified credential theft incidents affecting organizations using various self hosted file sharing platforms including some owncloud read more cross site request forgery in diagnostics app sep 9 2024 risk low cvss v3 base score 3 1 cvss v3 vector cvss 3 1 av n ac h pr n ui r s u c n i l a n cwe id 352 cwe name cross site request forgery csrf cve cve 2024 42014 description improper handling of csrf protection in the diagnostics app in combination with the read more url manipulation when sharing files via email sep 9 2024 risk medium cvss v3 base score 4 3 cvss v3 vector cvss 3 1 av n ac l pr l ui n s u c n i l a n cwe id 235 cwe name improper handling of extra parameters cve cve 2024 37009 description improper handling of url in sharing notification may allow an authenticated read more server side request forgery in federated sharing api sep 9 2024 risk medium cvss v3 base score 5 3 cvss v3 vector cvss 3 1 av n ac l pr n ui n s u c n i n a l cwe id 918 cwe name server side request forgery cve cve 2024 37012 description server side request forgery in federated sharing api may allow an unauthenticated read more insecure direct object reference in external storage sep 9 2024 risk high cvss v3 base score 8 8 cvss v3 vector cvss 3 1 av n ac l pr l ui n s u c h i h a h cwe id 639 cwe name insecure direct object reference cve cve 2024 37010 description insecure direct object reference in external storage configuration may allow an read more improper access control in svg preview generation sep 9 2024 risk medium cvss v3 base score 3 1 cvss v3 vector cvss 3 1 av n ac h pr l ui n s u c l i n a n cwe id 284 cwe name improper access control cve cve 2024 37011 description improper access control in svg preview generation may allow an authenticated attacker to read more improper validation in the user s avatar mechanism apr 19 2024 risk medium cvss v3 base score 4 3 cvss v3 vector av n ac l pr l ui n s u c n i n a l cr x ir x ar x cwe id 20 cwe name improper input validation cve cve 2024 26326 description improper validation in the user s avatar mechanism may allow an authenticated read more improper validation in the user profile metadata apr 19 2024 risk low cvss v3 base score 4 3 cvss v3 vector av n ac l pr l ui n s u c n i n a l cr x ir x ar x cwe id 20 cwe name improper input validation cve cve 2024 26325 description improper validation in the user profile metadata may allow an authenticated attacker to read more biometric authentication bypass apr 19 2024 risk medium cvss v3 base score 4 0 cvss v3 vector av p ac h pr l ui n s u c h i n a n cr x ir x ar x cwe id 284 cwe name improper access control cve cve 2024 26322 description improper validation in the biometric authentication process may allow an attacker to read more authentication bypass using pre signed urls apr 19 2024 risk high cvss v3 base score 7 5 cvss v3 vector av n ac l pr n ui n s u c n i h a n cr x ir x ar x cwe id 284 cwe name improper access control cve cve 2024 26321 description improper validation may allow an attacker to bypass authentication and gain access to read more denial of service in comments api apr 19 2024 risk medium cvss v3 base score 4 3 cvss v3 vector av n ac l pr l ui n s u c n i n a l cr x ir x ar x cwe id 20 cwe name improper input validation cve cve 2024 26320 description insufficient input validation in the comments plugin may allow an authenticated read more subdomain validation bypass nov 21 2023 risk critical cvss v3 base score 9 cvss v3 vector av n ac h pr n ui n s c c h i h a n cwe id cwe 284 cwe name improper access control description within the oauth2 app an attacker is able to pass in a specially crafted redirect url which bypasses the validation read more webdav api authentication bypass using pre signed urls nov 21 2023 risk high cvss v3 base score 9 8 cvss v3 vector av n ac l pr n ui n s u c h i h a h cwe id cwe 665 cwe name improper initialization description it is possible to access modify or delete any file without authentication if the username of the victim is known and read more disclosure of sensitive credentials and configuration in containerized deployments nov 21 2023 risk critical cvss v3 base score 10 cvss v3 vector av n ac l pr n ui n s c c h i h a h cwe id cwe 200 cwe name exposure of sensitive information to an unauthorized actor description the graphapi app relies on a third party library that provides a url when this read more edit of share permissions causes public links misbehaviour mar 14 2023 risk medium cvss v3 base score 0 cvss v3 vector cwe id cwe 440 cwe name expected behavior violation cve description changes to the permissions of a share where propagated to public links of child resources affected owncloud server 10 12 0 action taken read more sqlinjection in filecontentprovider kt mar 14 2023 risk low cvss v3 base score 5 cvss v3 vector av l ac l pr n ui r s u c l i l a n cwe id cwe 89 cwe name improper neutralization of special elements used in an sql command sql injection cve cve 2023 23948 description due to some insecure code in a exported read more insufficient path validation in android app feb 13 2023 risk low cvss v3 base score 5 cvss v3 vector av l ac l pr n ui r s c c l i l a n cwe id cwe 35 cwe name path traversal cve cve 2023 24804 description due to missing file path sanitation an attacker could read from and write to the android app s read more url spoofing in password reset mail oct 18 2022 risk medium cvss v3 base score 4 2 cvss v3 vector av n ac h pr n ui r s u c l i l a n cwe id cwe 923 cwe name improper restriction of communication channel to intended endpoints cve cve 2022 43679 description the docker image of the owncloud server contained a read more information disclosure in settings ui and api responses jun 6 2022 risk medium cvss v3 base score 5 7 cvss v3 vector av n ac l pr l ui r s u c h i n a n cwe id cwe 212 cwe name improper removal of sensitive information before storage or transfer cve cve 2022 31649 description the settings page and some api responses of a few read more security updates in desktop client may 23 2022 risk low cvss v3 base score 0 cvss v3 vector cwe id cwe name cve cve 2018 25032 description even though there are no known vulnerabilities in the owncloud desktop client we have updated the qt library which includes the zlib library this is a preventive measure read more access to internal files through owncloud android app mar 17 2022 risk low cvss v3 base score 2 8 cvss v3 vector av l ac l pr l ui r s u c l i n a n cwe id cwe 284 cwe name cwe 284 improper access control cve cve 2022 25339 description an attacker wich local access to a device with the owncloud android app could access read more owncloud android app lock bypass mar 17 2022 risk low cvss v3 base score 5 3 cvss v3 vector av p ac h pr h ui r s u c h i h a n cwe id cwe 284 cwe name cwe 284 improper access control cve cve 2022 25338 description an attacker with physical access to the device could bypass the app lock of the owncloud read more missing url validation allowed rce on the desktop client dec 21 2021 risk low cvss v3 base score 4 1 cvss v3 vector av l ac h pr h ui r s c c l i l a l cwe id cwe 99 cwe name improper control of resource identifiers resource injection cve cve 2021 44537 description a malicious server could achieve remote code execution on the read more server side request forgery ssrf through user_ldap app sep 8 2021 risk low cvss v3 base score 4 1 cvss v3 vector av n ac l pr h ui n s c c l i n a n cwe id cwe 918 cwe name server side request forgery ssrf cve cve 2021 40537 description server side request forgery ssrf vulnerability in the settings of the user_ldap app read more federated share recipient can increase permissions aug 2 2021 risk medium cvss v3 base score 5 7 cvss v3 vector av n ac l pr l ui r s u c n i h a n cwe id cwe 266 cwe name incorrect privilege assignment cve cve 2021 35946 description the receiver of a federated share could update the permissions granted to the receivers of read more shareinfo url doesn t verify file drop permissions aug 2 2021 risk low cvss v3 base score 4 3 cvss v3 vector av n ac l pr l ui n s u c l i n a n cwe id cwe 424 cwe name improper protection of alternate path cve cve 2021 35949 description the permission check for a file drop upload only share could be circumvented by read more session fixation on public links aug 2 2021 risk low cvss v3 base score 3 9 cvss v3 vector av l ac l pr l ui r s u c l i l a n cwe id cwe 384 cwe name session fixation cve cve 2021 35948 description the session cookies were not reset after authenticating for public links affected core 10 8 0 action read more full path and username disclosure in public links aug 2 2021 risk low cvss v3 base score 4 3 cvss v3 vector av n ac l pr l ui n s u c l i n a n cwe id cwe 209 cwe name generation of error message containing sensitive information cve cve 2021 35947 description by appending certain characters to the query parameters of a read more upload of malicious files to publicly shared folders jun 21 2021 risk medium cvss v3 base score 5 4 cvss v3 vector av n ac l pr l ui n s u c n i l a l cwe id cwe 459 cwe name incomplete cleanup cve cve 2021 33828 description it was possible to upload malicious files to a public share the malicious files were detected but read more arbitrary code execution through admin settings jun 21 2021 risk medium cvss v3 base score 6 6 cvss v3 vector av n ac l pr h ui n s c c l i l a l cwe id cwe 78 cwe name improper neutralization of special elements used in an os command os command injection cve cve 2021 33827 description in the administration settings read more authenticated account enumeration in sharing dialog may 17 2021 risk low cvss v3 base score 5 4 cvss v3 vector av n ac m au s c p i n a n cwe id cwe 200 cwe name exposure of sensitive information to an unauthorized actor cve cve 2021 29659 description the sharing dialog implements a user enumeration mitigation to prevent an read more dll injection in the owncloud desktop client feb 23 2021 risk medium cvss v3 base score 5 3 cvss v3 vector av l ac l pr n ui r s u c l i l a l cwe id cwe 114 cwe name process control description the released desktop client was loading development plugins from certain directories when they were present affected read more cross site request forgery in the ocs api dec 30 2020 risk medium cvss v3 base score 4 3 cvss v3 vector av n ac l pr n ui r s u c l i n a n cwe id cwe 352 cwe name cross site request forgery csrf description the csrf token was not properly checked on cookie authenticated requests against the ocs api affected read more missing user validation leading to information disclosure dec 30 2020 risk low cvss v3 base score 3 1 cvss v3 vector av n ac h pr n ui r s u c l i n a n cwe id cwe 20 cwe name improper input validation description deleting users with certain names caused system files to be deleted risk is higher for systems which allow users to read more reflected xss in login page forgot password functionallity aug 6 2020 risk medium cvss v3 base score 4 7 cvss v3 vector av n ac l pr n ui r s c c l i n a n cwe id cwe 79 cwe name improper neutralization of input during web page generation cross site scripting description the login page was not properly sanitizing exception read more bypassing app lock pattern passcode fingerprint lock android oc sa 2020 003 aug 3 2020 platform mobile clients versions date 8 3 2020 risk low cvss v3 base score 3 9 cvss v3 vector av p ac h pr l ui r s u c h i n a n cwe id cwe 312 cwe name cleartext storage of sensitive information description given an attacker has physical access creating a read more bypassing file firewall oc sa 2020 002 aug 3 2020 platform owncloud server versions n a date 8 3 2020 risk low cvss v3 base score 1 6 cvss v3 vector av n ac h pr n ui r s c c n i n a n cwe id cwe 791 cwe name incomplete filtering of special elements description when a share to a folder with upload rights was read more files_antivirus doesn t delete virus if uploaded through public link jul 31 2020 risk low cvss v3 base score 1 2 cvss v3 vector av n ac h pr l ui r s u c n i n a n cwe id cwe 280 cwe name improper handling of insufficient permissions or privileges description when using an object storage like s3 as the file store if a user creates a public read more security lock can be bypassed by changing the system date jun 16 2020 risk low cvss v3 base score 6 1 cvss v3 vector av p ac l pr n ui n s u c h i h a n cwe id cwe 15 cwe name external control of system or configuration setting description given an attacker has physical access to the device a faulty timestamp check allowed to read more deleting received group share for whole group feb 28 2020 platform owncloud server versions 10 2 0 date 2 28 2020 risk low cvss v3 base score 3 5 cvss v3 vector cvss 3 0 av n ac l pr l ui r s u c n i l a n cwe id 385 cwe name improper privilege management description a group share recipient can remove the received read more public link password bypass via image previews feb 28 2020 platform owncloud server versions 10 3 date 2 28 2020 risk low cvss v3 base score 3 1 cvss v3 vector cvss 3 1 av n ac h pr n ui r s u c l i n a n cwe id 284 cwe name improper access control description it was possible to access the preview image of a read more ssrf in add to your owncloud functionality feb 28 2020 platform owncloud server versions 10 3 10 3 1 date 2 28 2020 risk low cvss v3 base score 1 3 cvss v3 vector cvss 3 1 av n ac h pr l ui r s c c n i n a n cwe id 20 cwe name improper input validation description it is possible to force the owncloud server to read more access to all file versions of a user as soon as he has one share with the attacker feb 28 2020 platform owncloud server versions 10 3 0 date 2 28 2020 risk medium cvss v3 base score 6 8 cvss v3 vector cvss 3 1 av a ac l pr l ui n s c c h i n a n cwe id 648 cwe name incorrect use of privileged apis description an authenticated attacker can access all read more possibility to extend internal share permissions using the api jul 25 2019 platform owncloud server versions 10 0 0 date 7 25 2019 risk level high cvss v3 base score 8 improper privilege management cwe 269 description an attacker can extend the permission of a received subfolder share using the ocs api additional risk exists because read more xss in error page may 31 201...
|