ownCloud 'documents' Application ACL Check Security Bypass Vulnerability
BID:71370
Info
ownCloud 'documents' Application ACL Check Security Bypass Vulnerability
| Bugtraq ID: | 71370 |
| Class: | Design Error |
| CVE: |
CVE-2014-9048 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2014 12:00AM |
| Updated: | Nov 25 2014 12:00AM |
| Credit: | Lukas Reschke - ownCloud Inc. |
| Vulnerable: |
ownCloud ownCloud 7.0.2 ownCloud ownCloud 7.0.1 ownCloud ownCloud 7.0 ownCloud ownCloud 6.0.4 ownCloud ownCloud 6.0.1 ownCloud ownCloud 6.0.5 ownCloud ownCloud 6.0.3 ownCloud ownCloud 6.0.2 ownCloud ownCloud 6.0.0 |
| Not Vulnerable: |
ownCloud ownCloud 7.0.3 ownCloud ownCloud 6.0.6 |
Discussion
ownCloud 'documents' Application ACL Check Security Bypass Vulnerability
ownCloud is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass access control lists (ACLs) and gain access to restricted resources. This may aid in further attacks.
Versions prior to ownCloud 6.0.6 and 7.0.3 are vulnerable.
ownCloud is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass access control lists (ACLs) and gain access to restricted resources. This may aid in further attacks.
Versions prior to ownCloud 6.0.6 and 7.0.3 are vulnerable.
Solution / Fix
ownCloud 'documents' Application ACL Check Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ownCloud 'documents' Application ACL Check Security Bypass Vulnerability
References:
References:
- Documents Homepage (ownCloud)
- ownCloud Homepage (ownCloud)
- Bypass of shared files password protection in 'documents' application (oC-SA-201 (Lukas Reschke - ownCloud Inc.)