ownCloud 'Remember Me' Function Authentication Bypass Vulnerability
BID:55221
Info
ownCloud 'Remember Me' Function Authentication Bypass Vulnerability
| Bugtraq ID: | 55221 |
| Class: | Design Error |
| CVE: |
CVE-2012-4392 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 2012 12:00AM |
| Updated: | Sep 06 2012 03:39PM |
| Credit: | Julien Cayssol |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ownCloud 'Remember Me' Function Authentication Bypass Vulnerability
ownCloud is prone to an authentication-bypass vulnerability because it fails to restrict unauthenticated access.
Successful exploits may allow attackers to bypass security restrictions and gain unauthorized access; other attacks may also be possible.
ownCloud 4.0.6 is vulnerable; other versions may also be affected.
ownCloud is prone to an authentication-bypass vulnerability because it fails to restrict unauthenticated access.
Successful exploits may allow attackers to bypass security restrictions and gain unauthorized access; other attacks may also be possible.
ownCloud 4.0.6 is vulnerable; other versions may also be affected.
Exploit / POC
ownCloud 'Remember Me' Function Authentication Bypass Vulnerability
An attacker can carry out this attack using readily available network utilities.
An attacker can carry out this attack using readily available network utilities.
Solution / Fix
ownCloud 'Remember Me' Function Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
ownCloud 'Remember Me' Function Authentication Bypass Vulnerability
References:
References:
- ownCloud Homepage (ownCloud)