The external legacy SMB storage (not using php-libsmbclient) of ownCloud was not properly neutralizing all special elements which allows an adversary to execute arbitrary SMB commands. Effectively this allows an attacker to gain access to any file on the system or overwrite it, potentially leading to a PHP code execution.
Affects: owncloud < 8.1.2
Created owncloud tracking bugs for this issue:
Affects: fedora-all [bug 1274246]
Affects: epel-all [bug 1274247]
We do not ship ownCloud 8.1, and this bug only affects the 8.1 series, AFAICT. Even if it did affect the 8.0 or 7.0 series, there have been multiple stable releases of both those series since 8.1.2 came out, and a security fix would certainly have been backported to those if it were relevant.