Description
The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."
References (4)
Core 4
Core References
Patch, Vendor Advisory x_refsource_confirm
http://owncloud.org/security/advisories/oc-sa-2012-002/
Patch x_refsource_confirm
https://github.com/owncloud/core/commit/99cd922
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/11/30/3
Various Sources x_refsource_confirm
http://owncloud.org/changelog/
Scores
EPSS
0.0038
EPSS Percentile
59.4%
Details
CWE
CWE-255
Status
published
Products (14)
owncloud/owncloud
< 4.0.8
owncloud/owncloud_server
3.0.0
owncloud/owncloud_server
3.0.1
owncloud/owncloud_server
3.0.2
owncloud/owncloud_server
3.0.3
owncloud/owncloud_server
4.0.0
owncloud/owncloud_server
4.0.1
owncloud/owncloud_server
4.0.2
owncloud/owncloud_server
4.0.3
owncloud/owncloud_server
4.0.4
... and 4 more
Published
Dec 18, 2012
Tracked Since
Feb 18, 2026