CVE-2020-28646: High severity owncloud desktop client vulnerability
Published Feb 26, 2021
·Updated
ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.
Affected Software
1 affected component
ownCloud ownCloud Desktop Client<2.7
Event History
Feb 26, 2021
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this DLL Injection vulnerability?
The vulnerability ID for this DLL Injection vulnerability is CVE-2020-28646.
2
What is the severity of CVE-2020-28646?
The severity of CVE-2020-28646 is high, with a severity value of 7.8.
3
What is the affected software for CVE-2020-28646?
The affected software for CVE-2020-28646 is the ownCloud Desktop Client version up to exclusive 2.7.
4
How does the DLL Injection vulnerability in ownCloud owncloud/client before 2.7 occur?
The vulnerability in ownCloud owncloud/client before 2.7 occurs when the desktop client loaded development plugins from certain directories when they were present.
5
Is there a fix available for CVE-2020-28646?
Yes, ownCloud has released a fix for CVE-2020-28646. It is recommended to update to the latest version of the ownCloud Desktop Client.