CVE-2017-5865
Last modified
CVE-2017-5865 is a vulnerability of currently unknown severity. The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.. EPSS estimates a 1.09% chance of exploitation in the next 30 days.
Description
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Owncloud | Owncloud | <= 8.1.10 |
| Owncloud | Owncloud | 8.2.2 |
| Owncloud | Owncloud | 8.2.3 |
| Owncloud | Owncloud | 8.2.4 |
| Owncloud | Owncloud | 8.2.5 |
| Owncloud | Owncloud | 8.2.6 |
| Owncloud | Owncloud | 8.2.7 |
| Owncloud | Owncloud | 8.2.8 |
| Owncloud | Owncloud | 9.0.0 |
| Owncloud | Owncloud | 9.0.1 |
| Owncloud | Owncloud | 9.0.2 |
| Owncloud | Owncloud | 9.0.3 |
| Owncloud | Owncloud | 9.0.4 |
| Owncloud | Owncloud | 9.0.5 |
| Owncloud | Owncloud | 9.0.6 |
| Owncloud | Owncloud | 9.1.0 |
| Owncloud | Owncloud | 9.1.1 |
| Owncloud | Owncloud | 9.1.2 |
References
- http://www.securityfocus.com/bid/96425Third Party Advisory, VDB Entry
- https://owncloud.org/security/advisory/?id=oc-sa-2017-001Patch, Vendor Advisory
- http://www.securityfocus.com/bid/96425Third Party Advisory, VDB Entry
- https://owncloud.org/security/advisory/?id=oc-sa-2017-001Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5865?
How severe is CVE-2017-5865?
How do I fix CVE-2017-5865?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-5857Memory leak in the virgl_cmd_resource_unref function in hw/d…6.5
- CVE-2017-5858An incorrect implementation of "XEP-0280: Message Carbons" i…
- CVE-2017-5859On Cambium Networks cnPilot R200/201 devices before 4.3, the…9.8
- CVE-2017-5861Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2017-5863Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected…
- CVE-2017-5864Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected…
- CVE-2017-5866The autocomplete feature in the E-Mail share dialog in ownCl…
- CVE-2017-5867ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x bef…
- CVE-2017-5868CRLF injection vulnerability in the web interface in OpenVPN…
- CVE-2017-5869Directory traversal vulnerability in the file import feature…
- CVE-2017-5870Multiple cross-site scripting (XSS) vulnerabilities in ViMbA…
- CVE-2017-5871Odoo Version <= 8.0-20160726 and Version 9 is affected by: C…
Are you affected by CVE-2017-5865?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
