CVE-2017-5865
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user…
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.09% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- owncloud/owncloud
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/96425Third Party Advisory, VDB Entry
- https://owncloud.org/security/advisory/?id=oc-sa-2017-001Patch, Vendor Advisory
- http://www.securityfocus.com/bid/96425Third Party Advisory, VDB Entry
- https://owncloud.org/security/advisory/?id=oc-sa-2017-001Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.