CVE-2014-3963

ownCloud Server <6.0.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

ownCloud Server before 6.0.1 does not properly check permissions, which allows remote authenticated users to access arbitrary preview pictures via unspecified vectors.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
http://owncloud.org/about/security/advisories/oC-SA-2014-009/

Scores

EPSS 0.0013
EPSS Percentile 32.4%

Details

CWE
CWE-264
Status published
Products (1)
owncloud/owncloud < 6.0.0
Published Jun 04, 2014
Tracked Since Feb 18, 2026