CVE-2020-36252: Medium severity owncloud vulnerability
Published Feb 19, 2021
·Updated
ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.
Affected Software
2 affected components
ownCloud ownCloud>=10.0.9<10.3.1
ownCloud ownCloud Server>=10.0.9<10.3.1
Event History
Feb 19, 2021
CVE Published
via MITRE·06:59 AM
Data Sourced
via MITRE·06:59 AM
DescriptionSeverity
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-36252.
2
What is the severity of CVE-2020-36252?
The severity of CVE-2020-36252 is medium with a CVSS score of 5.7.
3
What is the affected software for CVE-2020-36252?
The affected software for CVE-2020-36252 is ownCloud Server 10.x before 10.3.1.
4
How does CVE-2020-36252 work?
CVE-2020-36252 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.
5
How can I fix CVE-2020-36252?
To fix CVE-2020-36252, update your ownCloud Server to version 10.3.1 or later.