CVE-2021-29659
Dashboard / Vulnerabilities / CVE-2021-29659
CVE-2021-29659
Published: 20 May 2021Last Modified: 9 Jul 2026
Summary:
Details: ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker can enumerate all users in a single request by entering three whitespaces. Secondary, the retrieval of all users on a large instance could cause higher than average load on the instance.
References: https://doc.owncloud.com/server/admin_manual/release_notes.html, https://owncloud.com/security-advisories/cve-2021-29659/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 119742ed5f9c01fd8fdae86457fd573533063a83
Fixed -None
Affected versions
10.7.0-NA
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
