ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.0.11"
},
{
"introduced": "0"
},
{
"last_affected": "8.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "8.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.3"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.4"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.5"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.6"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.8"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.9"
},
{
"introduced": "0"
},
{
"last_affected": "8.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "8.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "8.1.3"
},
{
"introduced": "0"
},
{
"last_affected": "8.1.4"
}
]
}