Lucene search

K
osvGoogleOSV:CVE-2021-35948
HistorySep 07, 2021 - 8:15 p.m.

CVE-2021-35948

2021-09-0720:15:07
Google
osv.dev
7
session fixation
owncloud server
password protection
software
vulnerability

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

32.1%

Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

32.1%