First published: Fri Mar 14 2014(Updated: )
The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud | =6.0.0 | |
ownCloud | =6.0.1 | |
ownCloud | <=5.0.14 | |
ownCloud | =3.0.0 | |
ownCloud | =3.0.1 | |
ownCloud | =3.0.2 | |
ownCloud | =3.0.3 | |
ownCloud | =4.0.0 | |
ownCloud | =4.0.1 | |
ownCloud | =4.0.2 | |
ownCloud | =4.0.3 | |
ownCloud | =4.0.4 | |
ownCloud | =4.0.5 | |
ownCloud | =4.0.6 | |
ownCloud | =4.0.7 | |
ownCloud | =4.0.8 | |
ownCloud | =4.0.9 | |
ownCloud | =4.0.10 | |
ownCloud | =4.0.11 | |
ownCloud | =4.0.12 | |
ownCloud | =4.0.13 | |
ownCloud | =4.0.14 | |
ownCloud | =4.0.15 | |
ownCloud | =4.0.16 | |
ownCloud | =4.5.0 | |
ownCloud | =4.5.1 | |
ownCloud | =4.5.2 | |
ownCloud | =4.5.3 | |
ownCloud | =4.5.4 | |
ownCloud | =4.5.5 | |
ownCloud | =4.5.6 | |
ownCloud | =4.5.7 | |
ownCloud | =4.5.8 | |
ownCloud | =4.5.9 | |
ownCloud | =4.5.10 | |
ownCloud | =4.5.11 | |
ownCloud | =4.5.12 | |
ownCloud | =4.5.13 | |
ownCloud | =5.0.0 | |
ownCloud | =5.0.1 | |
ownCloud | =5.0.2 | |
ownCloud | =5.0.3 | |
ownCloud | =5.0.4 | |
ownCloud | =5.0.5 | |
ownCloud | =5.0.6 | |
ownCloud | =5.0.7 | |
ownCloud | =5.0.8 | |
ownCloud | =5.0.9 | |
ownCloud | =5.0.10 | |
ownCloud | =5.0.11 | |
ownCloud | =5.0.12 | |
ownCloud | =5.0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2049 is classified as a medium severity vulnerability due to the potential unauthorized access to user files.
To fix CVE-2014-2049, upgrade ownCloud to version 5.0.15 or later, or to 6.0.2 or later.
CVE-2014-2049 affects ownCloud versions prior to 5.0.15 and 6.x prior to 6.0.2.
CVE-2014-2049 can be exploited by attackers to gain unauthorized access to user files through default Flash Cross Domain policies.
ownCloud recommends that users immediately update their installations to mitigate the CVE-2014-2049 vulnerability.