CVE-2017-5865

The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
VendorProductVersion
owncloudowncloud
𝑥
≤ 8.1.10
owncloudowncloud
8.2.2
owncloudowncloud
8.2.3
owncloudowncloud
8.2.4
owncloudowncloud
8.2.5
owncloudowncloud
8.2.6
owncloudowncloud
8.2.7
owncloudowncloud
8.2.8
owncloudowncloud
9.0.0
owncloudowncloud
9.0.1
owncloudowncloud
9.0.2
owncloudowncloud
9.0.3
owncloudowncloud
9.0.4
owncloudowncloud
9.0.5
owncloudowncloud
9.0.6
owncloudowncloud
9.1.0
owncloudowncloud
9.1.1
owncloudowncloud
9.1.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
owncloud
disco
dne
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
dne
trusty
dne
precise
ignored