The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate arbitrary classes and possibly execute arbitrary code via a crafted mount point option, related to "objectstore."
CVSS Vector
AV:N/AC:L/Au:S/C:C/I:C/A:COwncloud Server
APPOwncloud7.0.07.0.17.0.27.0.37.0.47.0.57.0.67.0.78.0.08.0.28.0.38.0.48.0.58.1.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
Related vulnerabilities
CVE-2023-49105CRITICAL9.8⚠ KEVPL ✓same product
OwnCloud: Pominięcie uwierzytelniania przez pre-signed URL (WebDAV API)
CVE-2014-2052CRITICAL9.8PL ✓same product
XXE w Zend Framework umożliwia odczyt plików w ownCloud Server
CVE-2016-1499HIGH8.5same product
ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to ...
CVE-2015-6500HIGH7.5same product
Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authent...
CVE-2015-4716HIGH10.0same product
Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8....