The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
References
Link | Resource |
---|---|
https://owncloud.com/security-advisories/cross-site-request-forgery-in-the-ocs-api/ | Vendor Advisory |
https://owncloud.com/security-advisories/cross-site-request-forgery-in-the-ocs-api/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 05:23
Type | Values Removed | Values Added |
---|---|---|
References | () https://owncloud.com/security-advisories/cross-site-request-forgery-in-the-ocs-api/ - Vendor Advisory |
Information
Published : 2021-02-09 19:15
Updated : 2024-11-21 05:23
NVD link : CVE-2020-28644
Mitre link : CVE-2020-28644
CVE.ORG link : CVE-2020-28644
JSON object : View
Products Affected
owncloud
- owncloud
CWE
CWE-352
Cross-Site Request Forgery (CSRF)