owncloud: multiple vulnerabilities
| Package(s): | owncloud | CVE #(s): | |||||||||
| Created: | January 25, 2016 | Updated: | January 27, 2016 | ||||||||
| Description: | From the ownCloud security advisories:
OC-SA-2016-001: A Cross-site scripting (XSS) vulnerability in the OCS discovery provider in ownCloud Servers allows remote attackers to inject arbitrary web script or HTML via the URL resulting in a reflected Cross-Site-Scripting. OC-SA-2016-002: Due to an incorrect usage of an ownCloud internal file system function the passed path to the file scanner was resolved relatively. An authenticated adversary may thus be able to get a listing of files existing on the filesystem. However, it is not possible to access any of these files. This causes a massive server load and thus an enumeration of the whole server content is unlikely due to the high risk of Denial of Service. OC-SA-2016-003: Due to a incorrect usage of the getOwner function of the ownCloud virtual filesystem,done authenticated users with incoming shares of other users are able to access files beginning with ".v" of the sharing user. This can only be exploited if the "files_versions" application is enabled on the server. OC-SA-2016-004: ownCloud returns exception error messages to the user in two different places, allowing an authenticated adversary to gain information about the installation path of the ownCloud instance. There is no further information disclosure. | ||||||||||
| Alerts: |
| ||||||||||
