ownCloud Password Reset Security Bypass Vulnerability
BID:53179
Info
ownCloud Password Reset Security Bypass Vulnerability
| Bugtraq ID: | 53179 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 20 2012 12:00AM |
| Updated: | Apr 23 2012 11:50AM |
| Credit: | luks |
| Vulnerable: |
ownCloud ownCloud 3.0.1 |
| Not Vulnerable: |
ownCloud ownCloud 3.0.2 |
Discussion
ownCloud Password Reset Security Bypass Vulnerability
ownCloud is prone to a security-bypass vulnerability.
An attacker can exploit this issue to change a user's password, thereby aiding in further attacks.
ownCloud 3.0.1 is vulnerable; other versions may also be affected.
ownCloud is prone to a security-bypass vulnerability.
An attacker can exploit this issue to change a user's password, thereby aiding in further attacks.
ownCloud 3.0.1 is vulnerable; other versions may also be affected.
Exploit / POC
ownCloud Password Reset Security Bypass Vulnerability
Attackers can exploit this issue through a browser.
The following exploit is available:
Attackers can exploit this issue through a browser.
The following exploit is available:
Solution / Fix
ownCloud Password Reset Security Bypass Vulnerability
Solution:
The vendor has released updates. Please see the references for details.
Solution:
The vendor has released updates. Please see the references for details.
References
ownCloud Password Reset Security Bypass Vulnerability
References:
References:
- ownCloud gitCommit (ownCloud)
- ownCloud Homepage (ownCloud)
- Weak password reset token & code exec in ownCloud 3.0.0 (luks)