ownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to apps/calendar/export.php.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-3373-1 owncloud security update
EUVD EUVD EUVD-2015-6608 ownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to apps/calendar/export.php.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 31 Mar 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Owncloud owncloud Server
CPEs cpe:2.3:a:owncloud:owncloud:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:8.0.3:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:8.0.4:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:8.0.5:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud:8.1.0:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:8.0.3:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:8.0.4:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:8.0.5:*:*:*:*:*:*:*
cpe:2.3:a:owncloud:owncloud_server:8.1.0:*:*:*:*:*:*:*
Vendors & Products Owncloud owncloud
Owncloud owncloud Server

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T07:29:24.456Z

Reserved: 2015-08-25T00:00:00

Link: CVE-2015-6670

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-10-26T14:59:09.577

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-6670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.