CVE-2020-10252: SSRF
An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/filessharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10252?
CVE-2020-10252 is a vulnerability in ownCloud before 10.4 that allows an authenticated attacker to interact with local services blindly or conduct a Denial of Service attack.
What is the severity of CVE-2020-10252?
The severity of CVE-2020-10252 is high with a CVSS score of 8.3.
How does CVE-2020-10252 affect ownCloud?
CVE-2020-10252 affects ownCloud versions up to exclusive version 10.4.0.
What is SSRF?
SSRF stands for Server-Side Request Forgery, which is a vulnerability that allows an attacker to make requests from the targeted server.
How can I fix CVE-2020-10252 in ownCloud?
To fix CVE-2020-10252 in ownCloud, you need to upgrade to version 10.4 or later.