The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://doc.owncloud.com/server/admin_manual/release_notes.html | release notes vendor advisory |
https://owncloud.com/security-advisories/cve-2021-35949/ | vendor advisory |