CVE-2021-33828: Malicious File Upload
The filesantivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33828?
CVE-2021-33828 is a vulnerability in the files_antivirus component before version 1.0.0 for ownCloud, which mishandles the deletion of malicious files uploaded to a public share upon detection.
What is the severity of CVE-2021-33828?
CVE-2021-33828 has a severity rating of 8.8 (high).
How does CVE-2021-33828 affect ownCloud?
CVE-2021-33828 affects the files_antivirus component of ownCloud, specifically versions before 1.0.0, by mishandling the deletion of malicious files uploaded to a public share.
How can I mitigate CVE-2021-33828 in ownCloud?
To mitigate CVE-2021-33828 in ownCloud, it is recommended to update the files_antivirus component to version 1.0.0 or later.
Where can I find more information about CVE-2021-33828?
More information about CVE-2021-33828 can be found in the ownCloud release notes and the ownCloud security advisories.