Executive brief
ownCloud, a popular file sharing and collaboration platform, contains a security flaw in its Gallery application. This vulnerability allows unauthorized individuals to bypass access controls and download private images directly from the server. This could lead to the exposure of sensitive personal or corporate visual data without the owner's consent.
Technical details
An improper access control vulnerability exists in the Gallery application of ownCloud Server. The flaw allows remote, unauthenticated attackers to bypass intended permission restrictions and download arbitrary image files by making direct requests to specific endpoints. This is classified as a failure in permissions and access control (CWE-264). The vulnerability affects ownCloud Server versions prior to 8.2.6 and 9.0.x versions prior to 9.0.3. Users are advised to upgrade to the patched versions to remediate this issue.
Affected products
- ownCloud ownCloud Server before 8.2.6, 9.x before 9.0.3
Timeline
- 2016-07-12: advisory: Vendor advisory OC-SA-2016-010 published
- 2017-01-23: disclosed: NVD publication date