ownCloud CSRF Token Leakage Information Disclosure Vulnerability
BID:66540
Info
ownCloud CSRF Token Leakage Information Disclosure Vulnerability
| Bugtraq ID: | 66540 |
| Class: | Design Error |
| CVE: |
CVE-2013-2086 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2014 12:00AM |
| Updated: | Mar 14 2014 12:00AM |
| Credit: | Reported by vendor. |
| Vulnerable: |
ownCloud ownCloud 5.0.5 ownCloud ownCloud 5.0.4 ownCloud ownCloud 5.0.3 ownCloud ownCloud 5.0.1 ownCloud ownCloud 5.0 ownCloud ownCloud 5.0.2 |
| Not Vulnerable: |
ownCloud ownCloud 5.0.6 |
Discussion
ownCloud CSRF Token Leakage Information Disclosure Vulnerability
ownCloud is prone to an unspecified remote information-disclosure vulnerability.
Attackers can leverage this issue to gain access to sensitive information. Information obtained may aid in further attacks.
ownCloud versions 5.0.x prior to 5.0.6 are vulnerable.
ownCloud is prone to an unspecified remote information-disclosure vulnerability.
Attackers can leverage this issue to gain access to sensitive information. Information obtained may aid in further attacks.
ownCloud versions 5.0.x prior to 5.0.6 are vulnerable.
Exploit / POC
ownCloud CSRF Token Leakage Information Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
ownCloud CSRF Token Leakage Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ownCloud CSRF Token Leakage Information Disclosure Vulnerability
References:
References:
- CSRF token leakage (oC-SA-2013-027) (ownCloud)
- ownCloud Homepage (ownCloud)