ownCloud 'documents' Application CVE-2014-9049 ACL Check Security Bypass Vulnerability
BID:71378
Info
ownCloud 'documents' Application CVE-2014-9049 ACL Check Security Bypass Vulnerability
| Bugtraq ID: | 71378 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-9049 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2014 12:00AM |
| Updated: | Nov 25 2014 12:00AM |
| Credit: | Lukas Reschke - ownCloud Inc. |
| Vulnerable: |
ownCloud ownCloud 7.0.2 ownCloud ownCloud 7.0.1 ownCloud ownCloud 7.0 ownCloud ownCloud 6.0.4 ownCloud ownCloud 6.0.1 ownCloud ownCloud 6.0.5 ownCloud ownCloud 6.0.3 ownCloud ownCloud 6.0.2 ownCloud ownCloud 6.0.0 |
| Not Vulnerable: |
ownCloud ownCloud 7.0.3 ownCloud ownCloud 6.0.6 |
Discussion
ownCloud 'documents' Application CVE-2014-9049 ACL Check Security Bypass Vulnerability
ownCloud is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass access control lists (ACLs) and gain access to restricted resources. This may aid in further attacks.
Versions prior to ownCloud 6.0.6 and 7.0.3 are vulnerable.
ownCloud is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass access control lists (ACLs) and gain access to restricted resources. This may aid in further attacks.
Versions prior to ownCloud 6.0.6 and 7.0.3 are vulnerable.
Exploit / POC
ownCloud 'documents' Application CVE-2014-9049 ACL Check Security Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
ownCloud 'documents' Application CVE-2014-9049 ACL Check Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ownCloud 'documents' Application CVE-2014-9049 ACL Check Security Bypass Vulnerability
References:
References:
- Documents Homepage (ownCloud)
- ownCloud Homepage (ownCloud)
- ACLs not properly enforced in 'documents' application (oC-SA-2014-025) (Lukas Reschke - ownCloud Inc.)