CVE-2014-2051: Code Injection
Published Jun 5, 2014
·Updated
ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to conduct an LDAP injection attack via unspecified vectors, as demonstrated using a "login query."
Affected Software
36 affected components
ownCloud ownCloud=6.0.0
ownCloud ownCloud=6.0.1
ownCloud ownCloud<=5.0.14
ownCloud ownCloud=5.0.0
ownCloud ownCloud=5.0.1
ownCloud ownCloud=5.0.2
ownCloud ownCloud=5.0.3
ownCloud ownCloud=5.0.4
ownCloud ownCloud=5.0.5
ownCloud ownCloud=5.0.6
ownCloud ownCloud=5.0.7
ownCloud ownCloud=5.0.8
ownCloud ownCloud=5.0.9
ownCloud ownCloud=5.0.10
ownCloud ownCloud=5.0.11
ownCloud ownCloud=5.0.12
ownCloud ownCloud=5.0.13
ownCloud ownCloud=5.0.14
ownCloud ownCloud Server=6.0.0
ownCloud ownCloud Server=6.0.1
ownCloud ownCloud Server<=5.0.14
ownCloud ownCloud Server=5.0.0
ownCloud ownCloud Server=5.0.1
ownCloud ownCloud Server=5.0.2
ownCloud ownCloud Server=5.0.3
ownCloud ownCloud Server=5.0.4
ownCloud ownCloud Server=5.0.5
ownCloud ownCloud Server=5.0.6
ownCloud ownCloud Server=5.0.7
ownCloud ownCloud Server=5.0.8
ownCloud ownCloud Server=5.0.9
ownCloud ownCloud Server=5.0.10
ownCloud ownCloud Server=5.0.11
ownCloud ownCloud Server=5.0.12
ownCloud ownCloud Server=5.0.13
ownCloud ownCloud Server=5.0.14
Remediation
Event History
Jun 5, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:44 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2051?
CVE-2014-2051 is categorized as a medium severity vulnerability due to its potential to allow LDAP injection attacks.
2
How do I fix CVE-2014-2051?
To fix CVE-2014-2051, upgrade your ownCloud server to version 5.0.15 or later, and 6.0.2 or later.
3
Which versions of ownCloud are affected by CVE-2014-2051?
CVE-2014-2051 affects ownCloud server versions prior to 5.0.15 and 6.0.x versions prior to 6.0.2.
4
What kind of attack can CVE-2014-2051 facilitate?
CVE-2014-2051 can facilitate remote attackers in conducting LDAP injection attacks via unspecified vectors.
5
Are there any specific vectors that CVE-2014-2051 exploits?
CVE-2014-2051 exploits unspecified vectors, particularly highlighted through a login query demonstration.