CVE-2021-35947: Medium severity owncloud vulnerability
Published Sep 7, 2021
·Updated
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.
Affected Software
1 affected component
ownCloud ownCloud<10.8.0
Event History
Sep 7, 2021
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-35947?
The severity of CVE-2021-35947 is medium with a CVSS score of 5.3.
2
What is the impact of CVE-2021-35947?
CVE-2021-35947 allows a remote attacker to see the internal path and username of a public share in ownCloud server before version 10.8.0.
3
How can an attacker exploit CVE-2021-35947?
An attacker can exploit CVE-2021-35947 by including invalid characters in the URL of a public share in ownCloud server before version 10.8.0.
4
How do I fix CVE-2021-35947?
To fix CVE-2021-35947, update ownCloud server to version 10.8.0 or newer.
5
Where can I find more information about CVE-2021-35947?
For more information about CVE-2021-35947, you can refer to the official release notes and security advisory provided by ownCloud.