VYPR
Unrated severityNVD Advisory· Published Jun 4, 2014· Updated May 6, 2026

CVE-2014-3838

CVE-2014-3838

Description

ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not properly check permissions, which allows remote authenticated users to read the names of files of other users by leveraging access to multiple accounts.

Affected products

21
  • cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*
    Range: <=5.0.15
  • OwnCloud/Server20 versions
    cpe:2.3:a:owncloud:owncloud_server:5.0.0:*:*:*:*:*:*:*+ 19 more
    • cpe:2.3:a:owncloud:owncloud_server:5.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.14:a:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:5.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:6.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:6.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:owncloud:owncloud_server:6.0.2:*:*:*:*:*:*:*
    • (no CPE)range: <5.0.16, >=6.0.0 <6.0.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.