PT-2021-9144 · Owncloud · Owncloud

Published

2021-02-19

·

Updated

2021-02-25

·

CVE-2020-10252

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions ownCloud versions prior to 10.4
Description An issue was discovered in ownCloud due to a Server-Side Request Forgery (SSRF) problem via the apps/files sharing/external remote parameter. This allows an authenticated attacker to interact with local services blindly, also known as Blind SSRF, or conduct a Denial Of Service attack.
Recommendations For versions prior to 10.4, update to version 10.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the apps/files sharing/external remote parameter to minimize the risk of exploitation.

Exploit

Fix

DoS

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10252

Affected Products

Owncloud