Vulnerability Description
ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove everyone else's access to that share.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Owncloud | Owncloud | < 10.3.0 |
References
- https://owncloud.com/security-advisories/deleting-received-group-share-for-wholeVendor Advisory
- https://owncloud.com/security-advisories/deleting-received-group-share-for-wholeVendor Advisory
FAQ
What is CVE-2020-36251?
CVE-2020-36251 is a vulnerability with a CVSS score of 3.5 (LOW). ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove everyone else's access to that share.
How severe is CVE-2020-36251?
CVE-2020-36251 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36251?
Check the references section above for vendor advisories and patch information. Affected products include: Owncloud Owncloud.