VYPR

CWE-708

Incorrect Ownership Assignment

BaseIncomplete

Description

The product assigns an owner to a resource, but the owner is outside of the intended control sphere.

This may allow the resource to be manipulated by actors outside of the intended control sphere.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (21)

page 2 of 2
  • CVE-2021-32689HigJul 12, 2021
    risk 0.00cvss 8.1epss 0.01

    Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier used username, they could get access to any chat message sent to the previous user with this username. The issue was patched in…