CVE Vulnerabilities

CVE-2013-0304

Published: Jun 05, 2014 | Modified: Jun 05, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. NOTE: this issue has been reported as a cross-site request forgery (CSRF) vulnerability, but due to lack of details, it is uncertain what the root cause is.

Affected Software

Name Vendor Start Version End Version
Owncloud Owncloud * 4.5.6 (including)
Owncloud Owncloud 4.5.0 (including) 4.5.0 (including)
Owncloud Owncloud 4.5.1 (including) 4.5.1 (including)
Owncloud Owncloud 4.5.2 (including) 4.5.2 (including)
Owncloud Owncloud 4.5.3 (including) 4.5.3 (including)
Owncloud Owncloud 4.5.4 (including) 4.5.4 (including)
Owncloud Owncloud 4.5.5 (including) 4.5.5 (including)
Owncloud Ubuntu oneiric *
Owncloud Ubuntu quantal *
Owncloud Ubuntu raring *
Owncloud Ubuntu saucy *
Owncloud Ubuntu upstream *

References