CVE-2017-9339: Medium severity ownCloud ownCloud vulnerability
Published Jul 17, 2017
·Updated
A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
Affected Software
1 affected component
ownCloud ownCloud<10.0.2
Event History
Jul 17, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9339?
CVE-2017-9339 has a medium severity rating due to its potential for unintended data exposure.
2
How do I fix CVE-2017-9339?
To fix CVE-2017-9339, upgrade your ownCloud Server to version 10.0.2 or later.
3
What problem does CVE-2017-9339 cause?
CVE-2017-9339 causes a logical error that may disclose valid share tokens for publicly shared calendars.
4
Are there any workarounds for CVE-2017-9339?
Temporary workarounds for CVE-2017-9339 include disabling public sharing of calendars until the software is upgraded.
5
Which versions of ownCloud are affected by CVE-2017-9339?
CVE-2017-9339 affects ownCloud Server versions prior to 10.0.2.