CVE-2021-35948: Medium severity owncloud vulnerability
Published Sep 7, 2021
·Updated
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.
Affected Software
1 affected component
ownCloud ownCloud<10.8.0
Event History
Sep 7, 2021
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-35948?
The severity of CVE-2021-35948 is medium with a severity score of 5.4.
2
How does CVE-2021-35948 impact ownCloud Server?
CVE-2021-35948 allows an attacker to bypass password protection on password protected public links in ownCloud Server before version 10.8.0.
3
How can an attacker exploit CVE-2021-35948?
An attacker can exploit CVE-2021-35948 by forcing a target client to use a controlled cookie.
4
Is there a fix for CVE-2021-35948?
Yes, a fix for CVE-2021-35948 is available in ownCloud Server version 10.8.0 or later.
5
Where can I find more information about CVE-2021-35948?
You can find more information about CVE-2021-35948 in the ownCloud Server release notes and the ownCloud security advisories.