CVE-2021-35949: Medium severity owncloud vulnerability
Published Sep 7, 2021
·Updated
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.
Affected Software
1 affected component
ownCloud ownCloud<10.8.0
Event History
Sep 7, 2021
CVE Published
via MITRE·06:59 PM
Data Sourced
via MITRE·06:59 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-35949.
2
What is the severity level of CVE-2021-35949?
CVE-2021-35949 has a severity level of medium (5.3).
3
How can an attacker exploit CVE-2021-35949?
An attacker can exploit CVE-2021-35949 by bypassing permission checks for upload only shares and listing metadata about the share.
4
Which software versions are affected by CVE-2021-35949?
The ownCloud Server versions before 10.8.0 are affected by CVE-2021-35949.
5
How can I fix CVE-2021-35949?
To fix CVE-2021-35949, upgrade to ownCloud Server version 10.8.0 or later.