CVE-2020-36249: High severity owncloud file firewall vulnerability
Published Feb 19, 2021
·Updated
The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares.
Affected Software
1 affected component
ownCloud File Firewall<2.8.0
Event History
Feb 19, 2021
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is CVE-2020-36249?
CVE-2020-36249 is a vulnerability in the File Firewall before 2.8.0 for ownCloud Server that allows bypassing of file-type restrictions for public shares.
2
What is the severity of CVE-2020-36249?
CVE-2020-36249 has a severity rating of high with a CVSS score of 7.5.
3
How does CVE-2020-36249 affect ownCloud Server?
CVE-2020-36249 affects ownCloud Server by allowing the bypassing of file-type restrictions for public shares.
4
Which version of File Firewall for ownCloud Server is affected by CVE-2020-36249?
Versions up to but not including 2.8.0 of File Firewall for ownCloud Server are affected by CVE-2020-36249.
5
How can I fix CVE-2020-36249?
To fix CVE-2020-36249, upgrade File Firewall to version 2.8.0 or higher for ownCloud Server.