Security Advisory

CVE-2021-35948

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-09-07 19:08:12
Last updated 2024-08-04 00:47:42
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.