CVE-2017-5865
Summary
| CVE | CVE-2017-5865 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-03-03 15:59:00 UTC |
| Updated | 2017-03-08 01:50:00 UTC |
| Description | The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Owncloud | Owncloud | 8.2.2 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.3 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.4 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.5 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.6 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.7 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.8 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.0 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.1 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.2 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.3 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.4 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.5 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.6 | All | All | All |
| Application | Owncloud | Owncloud | 9.1.0 | All | All | All |
| Application | Owncloud | Owncloud | 9.1.1 | All | All | All |
| Application | Owncloud | Owncloud | 9.1.2 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.2 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.3 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.4 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.5 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.6 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.7 | All | All | All |
| Application | Owncloud | Owncloud | 8.2.8 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.0 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.1 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.2 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.3 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.4 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.5 | All | All | All |
| Application | Owncloud | Owncloud | 9.0.6 | All | All | All |
| Application | Owncloud | Owncloud | 9.1.0 | All | All | All |
| Application | Owncloud | Owncloud | 9.1.1 | All | All | All |
| Application | Owncloud | Owncloud | 9.1.2 | All | All | All |
| Application | Owncloud | Owncloud | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisories – ownCloud | CONFIRM | owncloud.org | Patch, Vendor Advisory |
| ownCloud CVE-2017-5865 User Enumeration Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.