Hide Forgot
Due to a recent migration of the Gallery app to the new sharing endpoint a parameter changed from an integer to a string value. This value wasn't sanitized before and was thus now vulnerable to a Cross-Site-Scripting attack. To exploit this vulnerability an authenticated attacker has to share a folder with someone else, get them to open the shared folder in the Gallery app and open the sharing window there. Since ownCloud employs a strict Content-Security-Policy this vulnerability is only exploitable in browsers not supporting Content-Security-Policy. External References: https://owncloud.org/security/advisory/?id=oc-sa-2016-011 Upstream fix: https://github.com/owncloud/gallery/commit/6933d27afe518967bd1b60e6a7eacd88288929fc References: https://hackerone.com/reports/145355
Created owncloud tracking bugs for this issue: Affects: fedora-all [bug 1377397] Affects: epel-all [bug 1377398]
As per the tracking bugs, the current packages are at 9.0.4 and not affected by this.