PT-2017-18854 · Owncloud · Owncloud Server
CVE-2017-9339
·
Publicado
2017-07-17
·
Atualizado
2022-09-21
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ownCloud Server versions prior to 10.0.2
Description
A logical error in the software caused the disclosure of valid share tokens for public calendars, potentially granting an attacker access to publicly shared calendars without knowing the share token.
Recommendations
For versions prior to 10.0.2, update to version 10.0.2 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Owncloud Server