A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Owncloud | Owncloud | * | 10.8.0 (excluding) |
Owncloud | Ubuntu | trusty | * |
Owncloud | Ubuntu | xenial | * |