CVE-2014-2050: CSRF
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2050?
The severity of CVE-2014-2050 is medium (6.5).
How does the CSRF vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 work?
The CSRF vulnerability allows remote attackers to hijack user authentication for password reset requests by exploiting a crafted HTTP Host header.
What software versions are affected by CVE-2014-2050?
ownCloud Server versions before 5.0.15 and 6.0.x before 6.0.2 are affected.
How can I fix the CSRF vulnerability in ownCloud Server?
To fix the CSRF vulnerability, update ownCloud Server to version 5.0.15 or 6.0.2 or later.
Where can I find more information about CVE-2014-2050?
You can find more information about CVE-2014-2050 at the following references: [1](https://exchange.xforce.ibmcloud.com/vulnerabilities/91971), [2](https://owncloud.org/security/advisories/host-header-poisoning/), [3](https://www.securityfocus.com/bid/66221).