< go back to overview

Deleting received group share for whole group

Platform: ownCloud Server

Versions: 10.2.0,

Date: 2/28/2020

– Risk: Low
– CVSS v3 Base Score: 3.5
– CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
– CWE ID: 385
– CWE Name: Improper Privilege Management

A group-share recipient can remove the received group share for all group-recipients.
No data-loss occurs as the share can be re-created again.


– owncloud/core < v10.3.0

Action taken
Improve permission check when deleting groups.

Share this

By continuing to use the site, you agree to the use of cookies. more information

The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.