CVE-2021-44537: High severity owncloud desktop client vulnerability
Published Jan 15, 2022
·Updated
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
Affected Software
3 affected components
ownCloud ownCloud Desktop Client<2.9.2
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Event History
Jan 15, 2022
CVE Published
via MITRE·08:51 PM
Data Sourced
via MITRE·08:51 PM
Description
Frequently Asked Questions
1
What is CVE-2021-44537?
CVE-2021-44537 is a vulnerability in ownCloud owncloud/client before 2.9.2 that allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
2
What is the severity of CVE-2021-44537?
The severity of CVE-2021-44537 is high with a severity value of 7.8.
3
Which software versions are affected by CVE-2021-44537?
ownCloud owncloud/client versions before 2.9.2 are affected by CVE-2021-44537.
4
How can CVE-2021-44537 be exploited?
CVE-2021-44537 can be exploited by a server injecting a resource into the desktop client via a URL, which can lead to remote code execution.
5
Is there a fix available for CVE-2021-44537?
Yes, the fix for CVE-2021-44537 is to update ownCloud owncloud/client to version 2.9.2 or newer.