Giới thiệu chung
Dữ liệu gốcAn issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
Sản phẩm và phạm vi ảnh hưởng
Đang phân tích dữ liệu...
Chi tiết kỹ thuật
Đang phân tích dữ liệu...
Khả năng khai thác
Đang phân tích dữ liệu...
Tác động kỹ thuật
Đang phân tích dữ liệu...
Tác động đến tổ chức
Đang phân tích dữ liệu...
Cách khắc phục
Đang phân tích dữ liệu...
Cách phát hiện
Đang phân tích dữ liệu...