Vulnerability Description
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Owncloud | Files Antivirus | < 0.15.2 |
Related Weaknesses (CWE)
References
- https://owncloud.com/security-advisories/files-antivirus-doesnt-delete-virus-if-Vendor Advisory
- https://owncloud.com/security-advisories/files-antivirus-doesnt-delete-virus-if-Vendor Advisory
FAQ
What is CVE-2020-16144?
CVE-2020-16144 is a vulnerability with a CVSS score of 5.7 (MEDIUM). When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app w...
How severe is CVE-2020-16144?
CVE-2020-16144 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-16144?
Check the references section above for vendor advisories and patch information. Affected products include: Owncloud Files Antivirus.