Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the attacker.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
N/A
Vulnerability Title
ownCloud 安全漏洞
Vulnerability Description
ownCloud是美国ownCloud公司的一套个人云存储解决方案。 ownCloud oauth2 0.6.1 之前版本存在安全漏洞,该漏洞源于在 oauth2 应用程序中,攻击者能够传入特制的重定向 URL,该重定向 URL 会绕过验证代码,攻击者利用该漏洞可以重定向到攻击者控制的 TLD。
CVSS Information
N/A
Vulnerability Type
N/A