Skip to content

CVE-2014-3838

ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not properly check permissions, which allows remote authenticated users to read the names of files of other users by leveraging access to multiple accounts.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0013 (0.1%)
Percentile: 32.4%
EPSS: 2026-05-06

Affects

owncloud:owncloudowncloud:owncloud_server

Technical description

ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not properly check permissions, which allows remote authenticated users to read the names of files of other users by leveraging access to multiple accounts.

Published: 6/4/2014, 2:55:04 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam