First published: Thu May 20 2021(Updated: )
ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker can enumerate all users in a single request by entering three whitespaces. Secondary, the retrieval of all users on a large instance could cause higher than average load on the instance.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud ownCloud | =10.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29659 is an incorrect access control vulnerability in ownCloud 10.7, which can lead to remote information disclosure.
CVE-2021-29659 allows an attacker to enumerate all users in a single request by entering three whitespaces due to a bug in the related API endpoint.
CVE-2021-29659 has a severity value of 6.5, which is considered medium.
To fix CVE-2021-29659, you should update ownCloud to version 10.7.1 or later as recommended by the vendor.
You can find more information about CVE-2021-29659 in the ownCloud server release notes and the official ownCloud security advisories.