First published: Fri Feb 19 2021(Updated: )
An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud ownCloud | <10.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10254 is an issue discovered in ownCloud before 10.4 where an attacker can bypass authentication on a password-protected image by displaying its preview.
Versions up to exclusive ownCloud 10.4.0 are affected by CVE-2020-10254.
CVE-2020-10254 has a severity keyword of medium and a severity value of 5.9.
To fix CVE-2020-10254, update ownCloud to version 10.4.0 or later.
You can find more information about CVE-2020-10254 in the following references: [link 1](https://blog.hacktivesecurity.com/index.php?controller=post&action=view&id_post=44), [link 2](https://owncloud.com/security-advisories/public-link-password-bypass-via-image-previews/), [link 3](https://owncloud.org/changelog/server/).