CVE-2013-2149
Published: 14 March 2014
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.16 and 5.x before 5.0.7 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to shared files.
Notes
Author | Note |
---|---|
mdeslaur | owncloud packages in Ubuntu are now empty |
Priority
Status
Package | Release | Status |
---|---|---|
owncloud Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
precise |
Not vulnerable
|
|
quantal |
Ignored
(end of life)
|
|
raring |
Ignored
(end of life)
|
|
saucy |
Ignored
(end of life)
|
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Released
(5.0.7, 4.5.12, 4.0.16)
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
Patches: upstream: https://github.com/owncloud/core/commit/17b44bf upstream: https://github.com/owncloud/core/commit/752a316 |