Vulnerability Description
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Owncloud | Owncloud | < 10.6.0 |
Related Weaknesses (CWE)
References
- https://owncloud.com/security-advisories/cross-site-request-forgery-in-the-ocs-aVendor Advisory
- https://owncloud.com/security-advisories/cross-site-request-forgery-in-the-ocs-aVendor Advisory
FAQ
What is CVE-2020-28644?
CVE-2020-28644 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
How severe is CVE-2020-28644?
CVE-2020-28644 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28644?
Check the references section above for vendor advisories and patch information. Affected products include: Owncloud Owncloud.