ownCloud Server (ownCloud Core) 10.6.0 Release Candidate 1

CPE Details

ownCloud Server (ownCloud Core) 10.6.0 Release Candidate 1
10.6.0
2021-02-10
17h00 +00:00
2025-03-31
09h54 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:owncloud:owncloud:10.6.0:rc1:*:*:*:*:*:*

Informations

Vendor

owncloud

Product

owncloud

Version

10.6.0

Update

rc1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-43679 2022-11-09 23h00 +00:00 The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages.
5.3
Medium
CVE-2022-31649 2022-06-08 22h51 +00:00 ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
7.5
High
CVE-2021-35948 2021-09-07 17h08 +00:00 Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.
5.4
Medium
CVE-2021-35946 2021-09-07 17h04 +00:00 A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.
9.8
Critical
CVE-2021-35949 2021-09-07 16h59 +00:00 The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.
5.3
Medium
CVE-2021-35947 2021-09-07 16h49 +00:00 The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.
5.3
Medium