Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by leveraging a self-signed certificate and a connection to a server using its own self-signed certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OwnCloud Desktop Client 安全绕过漏洞
Vulnerability Description
ownCloud是德国OwnCloud公司的一套免费且开源的个人云存储解决方案,它提供文件管理、音乐存储、日历等功能。ownCloud Desktop Client是一个用于连接ownCloud服务器的桌面客户端。 OwnCloud Desktop Client 1.8.2之前版本中存在安全漏洞,该漏洞源于程序调用不正确的‘QNetworkReply::ignoreSslErrors’函数时会忽略列表中的的错误。攻击者可借助self-signed证书和与服务器的连接,利用该漏洞绕过用户设置的‘证书不可信’
CVSS Information
N/A
Vulnerability Type
N/A