CVE Vulnerabilities

CVE-2015-5954

Published: Oct 21, 2015 | Modified: Oct 22, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder.

Affected Software

Name Vendor Start Version End Version
Owncloud Owncloud * 6.0.8 (including)
Owncloud Owncloud 7.0.0 (including) 7.0.0 (including)
Owncloud Owncloud 7.0.1 (including) 7.0.1 (including)
Owncloud Owncloud 7.0.2 (including) 7.0.2 (including)
Owncloud Owncloud 7.0.3 (including) 7.0.3 (including)
Owncloud Owncloud 7.0.4 (including) 7.0.4 (including)
Owncloud Owncloud 7.0.5 (including) 7.0.5 (including)
Owncloud Owncloud 7.0.6 (including) 7.0.6 (including)
Owncloud Owncloud 8.0.0 (including) 8.0.0 (including)
Owncloud Owncloud 8.0.2 (including) 8.0.2 (including)
Owncloud Owncloud 8.0.3 (including) 8.0.3 (including)
Owncloud Owncloud 8.0.4 (including) 8.0.4 (including)
Owncloud Ubuntu upstream *

References