CVE-2020-36252

Source
https://cve.org/CVERecord?id=CVE-2020-36252
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36252.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-36252
Published
2021-02-19T07:15:13.810Z
Modified
2026-03-14T10:30:16.093818Z
Severity
  • 5.7 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.

References

Affected packages

Git / github.com/owncloud/core

Affected ranges

Type
GIT
Repo
https://github.com/owncloud/core
Events
Database specific
{
    "versions": [
        {
            "introduced": "10.0.9"
        },
        {
            "fixed": "10.3.1"
        }
    ]
}

Affected versions

v10.*
v10.0.10
v10.0.10RC1
v10.0.10RC2
v10.0.10RC3
v10.0.10RC4
v10.0.9
v10.1.0
v10.1.0RC1
v10.1.0RC2
v10.1.0beta
v10.3.0
v10.3.0RC1
v10.3.0alpha
v10.3.0alpha2
v10.3.1RC1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36252.json"