First published: Tue Sep 07 2021(Updated: )
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud ownCloud | <10.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-35947 is medium with a CVSS score of 5.3.
CVE-2021-35947 allows a remote attacker to see the internal path and username of a public share in ownCloud server before version 10.8.0.
An attacker can exploit CVE-2021-35947 by including invalid characters in the URL of a public share in ownCloud server before version 10.8.0.
To fix CVE-2021-35947, update ownCloud server to version 10.8.0 or newer.
For more information about CVE-2021-35947, you can refer to the official release notes and security advisory provided by ownCloud.