CVE Database
/

CVE-2015-5954

Back to search

CVE-2015-5954

Published: Oct 21, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-3373
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now