CVE-2017-5865

EUVD-2017-14941
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
owncloudowncloud
𝑥
≤ 8.1.10
owncloudowncloud
8.2.2
owncloudowncloud
8.2.3
owncloudowncloud
8.2.4
owncloudowncloud
8.2.5
owncloudowncloud
8.2.6
owncloudowncloud
8.2.7
owncloudowncloud
8.2.8
owncloudowncloud
9.0.0
owncloudowncloud
9.0.1
owncloudowncloud
9.0.2
owncloudowncloud
9.0.3
owncloudowncloud
9.0.4
owncloudowncloud
9.0.5
owncloudowncloud
9.0.6
owncloudowncloud
9.1.0
owncloudowncloud
9.1.1
owncloudowncloud
9.1.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
owncloud
artful
dne
bionic
dne
cosmic
dne
disco
dne
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne