An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.
References
Link | Resource |
---|---|
https://owncloud.org/changelog/server/ | Product Release Notes |
https://owncloud.com/security-advisories/public-link-password-bypass-via-image-previews/ | Vendor Advisory |
https://blog.hacktivesecurity.com/index.php?controller=post&action=view&id_post=44 | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-02-18 23:15
Updated : 2021-02-25 12:38
NVD link : CVE-2020-10254
Mitre link : CVE-2020-10254
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
owncloud
- owncloud