CVE-2015-5955: Medium severity owncloud vulnerability
Published Oct 29, 2015
·Updated
ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain sensitive credential and cookie information by reading authentication headers.
Affected Software
2 affected components
ownCloud Owncloud Iphone Os<3.4.4
ownCloud Owncloud Client Iphone Os<3.4.4
Event History
Oct 29, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-5955?
CVE-2015-5955 is considered a high severity vulnerability due to the potential exposure of sensitive credential and cookie information.
2
How do I fix CVE-2015-5955?
To fix CVE-2015-5955, users should upgrade their ownCloud iOS app to version 3.4.4 or later.
3
What versions of the ownCloud iOS app are affected by CVE-2015-5955?
CVE-2015-5955 affects all versions of the ownCloud iOS app prior to 3.4.4.
4
What information can be compromised due to CVE-2015-5955?
Due to CVE-2015-5955, sensitive credential and cookie information may be exposed to remote instance administrators.
5
Does CVE-2015-5955 affect only iOS devices?
Yes, CVE-2015-5955 specifically affects the ownCloud iOS app on iPhone devices.