The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate arbitrary classes and possibly execute arbitrary code via a crafted mount point option, related to "objectstore."
References
Configurations
Configuration 1 (hide)
|
History
31 Mar 2025, 11:54
Type | Values Removed | Values Added |
---|---|---|
First Time |
Owncloud owncloud Server
|
|
CPE | cpe:2.3:a:owncloud:owncloud:8.0.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.6:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:8.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:8.0.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.7:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:8.0.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.1:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:7.0.0:*:*:*:*:*:*:* |
cpe:2.3:a:owncloud:owncloud_server:8.0.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.7:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:8.0.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.1:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.6:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:8.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:8.0.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:7.0.0:*:*:*:*:*:*:* |
21 Nov 2024, 02:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.debian.org/security/2015/dsa-3373 - | |
References | () https://github.com/owncloud/core/pull/18558 - | |
References | () https://owncloud.org/security/advisory/?id=oc-sa-2015-018 - Vendor Advisory |
Information
Published : 2015-10-26 15:59
Updated : 2025-03-31 11:54
NVD link : CVE-2015-7699
Mitre link : CVE-2015-7699
CVE.ORG link : CVE-2015-7699
JSON object : View
Products Affected
owncloud
- owncloud_server
CWE
CWE-20
Improper Input Validation