Overview
Original source dataAn issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
Affected products and scope
Analyzing data...
Technical details
Analyzing data...
Exploitability
Analyzing data...
Technical impact
Analyzing data...
Business impact
Analyzing data...
Remediation
Analyzing data...
Detection
Analyzing data...