CVE-2014-9044: Infoleak
Published Feb 4, 2015
·Updated
Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote attackers to obtain sensitive information via a brute force attack.
Affected Software
6 affected components
ownCloud ownCloud=7.0.0
ownCloud ownCloud=7.0.1
ownCloud ownCloud=7.0.2
ownCloud ownCloud Server=7.0.0
ownCloud ownCloud Server=7.0.1
ownCloud ownCloud Server=7.0.2
Event History
Feb 4, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-9044?
CVE-2014-9044 is classified as a medium severity vulnerability due to the potential for sensitive information disclosure.
2
How do I fix CVE-2014-9044?
To mitigate CVE-2014-9044, upgrade ownCloud to version 7.0.3 or later.
3
What type of attack can exploit CVE-2014-9044?
CVE-2014-9044 can be exploited through a brute force attack targeting the concatenated file names of CSS and JS files.
4
What versions of ownCloud are affected by CVE-2014-9044?
CVE-2014-9044 affects ownCloud versions 7.0.0, 7.0.1, and 7.0.2.
5
What information can attackers obtain through CVE-2014-9044?
Attackers can obtain sensitive information from the original CSS and JS file paths by exploiting CVE-2014-9044.