Security Advisory

CVE-2012-5607

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-12-18 01:00:00
Last updated 2024-09-16 18:03:39
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."