First published: Fri Feb 19 2021(Updated: )
An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud ownCloud | <10.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10252 is a vulnerability in ownCloud before 10.4 that allows an authenticated attacker to interact with local services blindly or conduct a Denial of Service attack.
The severity of CVE-2020-10252 is high with a CVSS score of 8.3.
CVE-2020-10252 affects ownCloud versions up to exclusive version 10.4.0.
SSRF stands for Server-Side Request Forgery, which is a vulnerability that allows an attacker to make requests from the targeted server.
To fix CVE-2020-10252 in ownCloud, you need to upgrade to version 10.4 or later.