CVE-2014-2052: XEE
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-2052?
CVE-2014-2052 is a vulnerability in Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, that allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
How does CVE-2014-2052 affect ownCloud Server?
CVE-2014-2052 affects ownCloud Server versions before 5.0.15 and 6.0.x before 6.0.2.
What is the severity of CVE-2014-2052?
CVE-2014-2052 has a severity rating of 9.8 (Critical).
How can CVE-2014-2052 be exploited?
CVE-2014-2052 can be exploited by remote attackers using an XML External Entity (XXE) attack to read arbitrary files or cause a denial of service.
How can I fix CVE-2014-2052?
To fix CVE-2014-2052, users should update ownCloud Server to version 5.0.15 or 6.0.2.