CVE-2021-35946: Critical severity owncloud vulnerability
Published Sep 7, 2021
·Updated
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.
Affected Software
1 affected component
ownCloud ownCloud<10.8.0
Event History
Sep 7, 2021
CVE Published
via MITRE·07:04 PM
Data Sourced
via MITRE·07:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-35946?
The severity of CVE-2021-35946 is critical with a severity value of 9.8.
2
How does CVE-2021-35946 affect ownCloud?
CVE-2021-35946 affects ownCloud versions before 10.8.
3
What is the impact of CVE-2021-35946?
CVE-2021-35946 allows a receiver of a federated share to update permissions and elevate their own permissions.
4
How can I fix CVE-2021-35946?
To fix CVE-2021-35946, update ownCloud to version 10.8 or later.
5
Where can I find more information about CVE-2021-35946?
You can find more information about CVE-2021-35946 in the release notes of ownCloud and the security advisory from ownCloud.